Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-3689


Vulnerability Score 7.5 7.5
CVE Id CVE-2006-3689
Last Modified 05 Sep 2008 05:07:48
Published 21 Jul 2006 10:03:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE



** DISPUTED ** PHP remote file inclusion vulnerability in user-func.php in Codeworks Gnomedia SubberZ[Lite] allows remote attackers to execute arbitrary PHP code via a URL in the myadmindir parameter. NOTE: this issue has been disputed by a third party that claims that " the myadmindir variable is set before any GET variables are processed."

Vulnerable Systems


  • Codeworks Gnomedia Subberz Lite


XF - subberzlite-userfunc-file-include(27748)

BID - 18990

BUGTRAQ - 20060717 Re: SubberZ[Lite] - Remote File Include

BUGTRAQ - 20060714 SubberZ[Lite] - Remote File Include

OSVDB - 28592

SREASON - 1246

Last Updated: 27 May 2016 10:43:06