Multiple PHP remote file inclusion vulnerabilities in SQuery 4.5 and earlier, as used in products such as Autonomous LAN party (ALP), allow remote attackers to execute arbitrary PHP code via a URL in the libpath parameter to scripts in the lib directory including (1) ase.php, (2) devi.php, (3) doom3.php, (4) et.php, (5) flashpoint.php, (6) gameSpy.php, (7) gameSpy2.php, (8) gore.php, (9) gsvari.php, (10) halo.php, (11) hlife.php, (12) hlife2.php, (13) igi2.php, (14) main.lib.php, (15) netpanzer.php, (16) old_hlife.php, (17) pkill.php, (18) q2a.php, (19) q3a.php, (20) qworld.php, (21) rene.php, (22) rvbshld.php, (23) savage.php, (24) simracer.php, (25) sof1.php, (26) sof2.php, (27) unreal.php, (28) ut2004.php, and (29) vietcong.php
Published Apr 10, 2006
7.5
HIGHCVSS 2.0
EPSS 7.59%
Description
Multiple PHP remote file inclusion vulnerabilities in SQuery 4.5 and earlier, as used in products such as Autonomous LAN party (ALP), allow remote attackers to execute arbitrary PHP code via a URL in the libpath parameter to scripts in the lib directory including (1) ase.php, (2) devi.php, (3) doom3.php, (4) et.php, (5) flashpoint.php, (6) gameSpy.php, (7) gameSpy2.php, (8) gore.php, (9) gsvari.php, (10) halo.php, (11) hlife.php, (12) hlife2.php, (13) igi2.php, (14) main.lib.php, (15) netpanzer.php, (16) old_hlife.php, (17) pkill.php, (18) q2a.php, (19) q3a.php, (20) qworld.php, (21) rene.php, (22) rvbshld.php, (23) savage.php, (24) simracer.php, (25) sof1.php, (26) sof2.php, (27) unreal.php, (28) ut2004.php, and (29) vietcong.php. NOTE: the lib/armygame.php vector is already covered by CVE-2006-1610. The provenance of most of these additional vectors is unknown, although likely from post-disclosure analysis. NOTE: this only occurs when register_globals is disabled.
Affected products
Remediation
No remediation recorded yet.
References (41)
- http://liz0zim.no-ip.org/alp.txt x_refsource_MISCExploit
- http://secunia.com/advisories/19482 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/19588 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securityreason.com/securityalert/679 third-party-advisoryx_refsource_SREASON
- http://securitytracker.com/id?1015884 vdb-entryx_refsource_SECTRACKExploit
- http://www.blogcu.com/Liz0ziM/431845/ x_refsource_MISCExploitURL Repurposed
- http://www.osvdb.org/24401 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24402 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24403 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24404 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24405 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24406 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24407 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/24408 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24409 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24410 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24411 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24412 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24413 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24414 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24415 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24416 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24417 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24418 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24419 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24420 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24421 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24422 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24423 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24424 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24425 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24426 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24427 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24428 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24429 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/archive/1/430289/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/439874/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/441015/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/17434 vdb-entryx_refsource_BIDExploit
- http://www.vupen.com/english/advisories/2006/1284 vdb-entryx_refsource_VUPENVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-1689 Advisory
Change history (0)
No recorded changes yet.