Vulnerabilities > CVE-2006-7184 - Remote File Include vulnerability in Exhibit Engine Toroot Parameter

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
photography-on-the-net
nessus
exploit available

Summary

Multiple PHP remote file inclusion vulnerabilities in Exhibit Engine (EE) 1.22, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the toroot parameter to (1) fetchsettings.php or (2) fstyles.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Vulnerable Configurations

Part Description Count
Application
Photography-On-The-Net
1

Exploit-Db

  • descriptionExhibit Engine 1.22 fetchsettings.php toroot Parameter Remote File Inclusion. CVE-2006-7184 . Webapps exploit for php platform
    idEDB-ID:28873
    last seen2016-02-03
    modified2006-10-30
    published2006-10-30
    reporterCyber Security
    sourcehttps://www.exploit-db.com/download/28873/
    titleExhibit Engine 1.22 fetchsettings.php toroot Parameter Remote File Inclusion
  • descriptionExhibit Engine 1.22 fstyles.php toroot Parameter Remote File Inclusion. CVE-2006-7184. Webapps exploit for php platform
    idEDB-ID:28874
    last seen2016-02-03
    modified2006-10-30
    published2006-10-30
    reporterCyber Security
    sourcehttps://www.exploit-db.com/download/28874/
    titleExhibit Engine 1.22 fstyles.php toroot Parameter Remote File Inclusion

Nessus

NASL familyCGI abuses
NASL idEXHIBIT_ENGINE_RFI.NASL
descriptionThe remote web server is running Exhibit Engine, a PHP based photo gallery management system. The version of Exhibit Engine installed on the remote host fails to sanitize input to the
last seen2020-06-01
modified2020-06-02
plugin id23640
published2006-11-14
reporterThis script is Copyright (C) 2006-2018 Justin Seitz
sourcehttps://www.tenable.com/plugins/nessus/23640
titleExhibit Engine styles.php toroot Parameter Remote File Inclusion