CVE-2006-0824

Multiple unspecified vulnerabilities in lib-common.php in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attackers to include arbitrary local files and execute arbitrary code via (1) absolute paths in unspecified parameters and (2) the language cookie, as demonstrated for code execution using error.log.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:geeklog:geeklog:1.3.11:*:*:*:*:*:*:*
cpe:2.3:a:geeklog:geeklog:1.3.11_sr1:*:*:*:*:*:*:*
cpe:2.3:a:geeklog:geeklog:1.3.11_sr2:*:*:*:*:*:*:*
cpe:2.3:a:geeklog:geeklog:1.3.11_sr3:*:*:*:*:*:*:*
cpe:2.3:a:geeklog:geeklog:1.4.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:07

Type Values Removed Values Added
References () http://secunia.com/advisories/18920 - Patch, Vendor Advisory () http://secunia.com/advisories/18920 - Patch, Vendor Advisory
References () http://www.geeklog.net/article.php/geeklog-1.4.0sr1 - Patch () http://www.geeklog.net/article.php/geeklog-1.4.0sr1 - Patch
References () http://www.gulftech.org/?node=research&article_id=00102-02192006 - () http://www.gulftech.org/?node=research&article_id=00102-02192006 -
References () http://www.osvdb.org/23349 - () http://www.osvdb.org/23349 -
References () http://www.securityfocus.com/archive/1/425506/100/0/threaded - () http://www.securityfocus.com/archive/1/425506/100/0/threaded -
References () http://www.securityfocus.com/bid/16755 - () http://www.securityfocus.com/bid/16755 -
References () http://www.vupen.com/english/advisories/2006/0661 - () http://www.vupen.com/english/advisories/2006/0661 -

Information

Published : 2006-02-21 23:02

Updated : 2024-11-21 00:07


NVD link : CVE-2006-0824

Mitre link : CVE-2006-0824

CVE.ORG link : CVE-2006-0824


JSON object : View

Products Affected

geeklog

  • geeklog