HIGH
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Live Helper 1.8 allow remote attackers to include and execute arbitrary PHP code via the abs_path parameter in (1) initiate.php, (2) waiting.php, (3) welcome.php, (4) admin/index.php, (5) javascript.php, (6) checkchat.php, and (7) blank.php
Published Mar 29, 2006
7.5
HIGHCVSS 2.0
EPSS 4.81%
Description
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Live Helper 1.8 allow remote attackers to include and execute arbitrary PHP code via the abs_path parameter in (1) initiate.php, (2) waiting.php, (3) welcome.php, (4) admin/index.php, (5) javascript.php, (6) checkchat.php, and (7) blank.php.
Affected products
No data.
- 1.8
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (16)
- http://secunia.com/advisories/19428 third-party-advisoryx_refsource_SECUNIAExploitVendor Advisory
- http://www.osvdb.org/24193 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24194 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24195 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24196 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24197 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24198 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24199 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/archive/1/428976/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/437648/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/437741/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/18509 vdb-entryx_refsource_BID
- http://www.turnkeywebtools.com/forum/showthread.php?p=10415 x_refsource_MISCPatch
- http://www.vupen.com/english/advisories/2006/1137 vdb-entryx_refsource_VUPEN
- http://www.worlddefacers.de/Public/WD-TMPLH.txt x_refsource_MISCExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25489 vdb-entryx_refsource_XF
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 29, 2006
Updated Aug 7, 2024
Reserved Mar 28, 2006
Link CVE-2006-1477
CISA Vulnrichment
Updated n/a