Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-1563

Overview

Vulnerability Score 7.6 7.6
CVE Id CVE-2006-1563
Last Modified 07 Mar 2011 09:33:19
Published 31 Mar 2006 06:06:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity HIGH
Authentication NONE

CVE-2006-1563

Summary

Direct static code injection vulnerability in config.php in vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allows remote administrators to execute arbitrary PHP code into the config file, which is included other [V]Book scripts.

Vulnerable Systems

Application

  • Vscripts Vbook 2.0


References

VUPEN - ADV-2006-1174

MISC - http://evuln.com/vulns/111

XF - vbook-config-file-include(25522)

BUGTRAQ - 20060411 [eVuln] [V]Book Multiple Vulnerabilities

OSVDB - 24272

SECUNIA - 19448


Last Updated: 27 May 2016 10:42:06