Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-2859

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2006-2859
Last Modified 05 Sep 2008 05:05:37
Published 06 Jun 2006 04:06:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2006-2859

Summary

** DISPUTED ** PHP remote file inclusion vulnerability in MyBloggie 2.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mybloggie_root_path parameter to (1) admin.php or (2) scode.php. NOTE: this issue has been disputed in multiple third party followups, which say that the MyBloggie source code does not demonstrate the issue, so it might be the result of another module. CVE analysis as of 20060605 agrees with the dispute. In addition, scode.php is not part of the MyBloggie distribution.

Vulnerable Systems

Application

  • Mywebland Mybloggie 2.1.1


References

BID - 18241

BUGTRAQ - 20060606 Re: # MHG Security Team --- MyBloggie 2.1.1 version Remote File Include Vulnerabilit

BUGTRAQ - 20060603 Re: # MHG Security Team --- MyBloggie 2.1.1 version Remote File Include Vulnerabilit

BUGTRAQ - 20060602 # MHG Security Team --- MyBloggie 2.1.1 version Remote File Include Vulnerabilit

SREASON - 1049


Last Updated: 27 May 2016 10:42:48