CVE-2006-2877

PHP remote file inclusion vulnerability in Bookmark4U 2.0.0 and earlier allows remote attackers to include arbitrary PHP files via the include_prefix parameter in (1) inc/dbase.php, (2) inc/config.php, (3) inc/common.php, and (4) inc/function.php. NOTE: it has been reported that the inc directory is protected by a .htaccess file, so this issue only applies in certain environments or configurations.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sangwan_kim:bookmark4u:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:12

Type Values Removed Values Added
References () http://secunia.com/advisories/19758 - () http://secunia.com/advisories/19758 -
References () http://securityreason.com/securityalert/1058 - () http://securityreason.com/securityalert/1058 -
References () http://securitytracker.com/id?1016224 - () http://securitytracker.com/id?1016224 -
References () http://www.osvdb.org/26599 - () http://www.osvdb.org/26599 -
References () http://www.osvdb.org/26600 - () http://www.osvdb.org/26600 -
References () http://www.osvdb.org/26601 - () http://www.osvdb.org/26601 -
References () http://www.osvdb.org/26602 - () http://www.osvdb.org/26602 -
References () http://www.securityfocus.com/archive/1/435964/100/0/threaded - () http://www.securityfocus.com/archive/1/435964/100/0/threaded -
References () http://www.securityfocus.com/archive/1/436027/100/0/threaded - () http://www.securityfocus.com/archive/1/436027/100/0/threaded -
References () http://www.securityfocus.com/bid/18281 - () http://www.securityfocus.com/bid/18281 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/26933 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/26933 -

Information

Published : 2006-06-07 00:02

Updated : 2024-11-21 00:12


NVD link : CVE-2006-2877

Mitre link : CVE-2006-2877

CVE.ORG link : CVE-2006-2877


JSON object : View

Products Affected

sangwan_kim

  • bookmark4u