MEDIUM
Multiple PHP remote file inclusion vulnerabilities in the Content Management module ("Content manager") for PHProjekt 0.6.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via the path_pre parameter in (1) cm_lib.inc.php, (2) doc/br.edithelp.php, (3) doc/de.edithelp.php, (4) doc/ct.edithelp.php, (5) userrating.php, and (6) listing.php, a different set of vectors than CVE-2006-4204
Published Sep 7, 2006
5.1
MEDIUMCVSS 2.0
EPSS 2.97%
Description
Affected products
Remediation
Metrics
References (6)
Change history (0)
No recorded changes yet.