Vulnerabilities > CVE-2006-7183 - Remote File Include vulnerability in Exhibit Engine 2

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
photography-on-the-net
critical
nessus
exploit available

Summary

PHP remote file inclusion vulnerability in styles.php in Exhibit Engine (EE) 1.22 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the toroot parameter.

Vulnerable Configurations

Part Description Count
Application
Photography-On-The-Net
1

Exploit-Db

descriptionExhibit Engine <= 1.22 (styles.php) Remote File Include Vulnerability. CVE-2006-7183. Webapps exploit for php platform
fileexploits/php/webapps/2850.txt
idEDB-ID:2850
last seen2016-01-31
modified2006-11-25
platformphp
port
published2006-11-25
reporterKacper
sourcehttps://www.exploit-db.com/download/2850/
titleExhibit Engine <= 1.22 styles.php Remote File Include Vulnerability
typewebapps

Nessus

NASL familyCGI abuses
NASL idEXHIBIT_ENGINE_RFI.NASL
descriptionThe remote web server is running Exhibit Engine, a PHP based photo gallery management system. The version of Exhibit Engine installed on the remote host fails to sanitize input to the
last seen2020-06-01
modified2020-06-02
plugin id23640
published2006-11-14
reporterThis script is Copyright (C) 2006-2018 Justin Seitz
sourcehttps://www.tenable.com/plugins/nessus/23640
titleExhibit Engine styles.php toroot Parameter Remote File Inclusion