Vulnerabilities > CVE-2006-7173 - Remote Security vulnerability in PHP-Stats

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
php-stats
critical
exploit available

Summary

Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to execute arbitrary PHP code via a crafted option_new[report_w_day] parameter in a preferenze action, which can be later accessed via option/php-stats-options.php.

Vulnerable Configurations

Part Description Count
Application
Php-Stats
1

Exploit-Db

descriptionPhp-Stats <= 0.1.9.1b (php-stats-options.php) admin 2 exec() eExploit. CVE-2006-7173. Webapps exploit for php platform
fileexploits/php/webapps/3502.php
idEDB-ID:3502
last seen2016-01-31
modified2007-03-17
platformphp
port
published2007-03-17
reporterrgod
sourcehttps://www.exploit-db.com/download/3502/
titlePhp-Stats <= 0.1.9.1b php-stats-options.php admin 2 exec eExploit
typewebapps