Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-1781

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2006-1781
Last Modified 22 Aug 2011 12:00:00
Published 13 Apr 2006 06:02:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2006-1781

Summary

PHP remote file inclusion vulnerability in functions.php in Circle R Monster Top List (MTL) 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. NOTE: It was later reported that 1.4.2 and earlier are affected.

Vulnerable Systems

Application

  • Circle R Monster Top List 1.4.2


References

XF - monstertoplist-functions-file-include(25774)

VUPEN - ADV-2006-1350

BID - 23074

BID - 17546

OSVDB - 24650

MILW0RM - 3530

SECUNIA - 19688

MISC - http://pridels0.blogspot.com/2006/04/monstertoplist.html


Last Updated: 27 May 2016 10:42:10