CVE-2006-4311

PHP remote file inclusion vulnerability in Sonium Enterprise Adressbook 0.2 allows remote attackers to execute arbitrary PHP code via the folder parameter in multiple files in the plugins directory, as demonstrated by plugins/1_Adressbuch/delete.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sonium:enterprise_adressbook:0.2:*:*:*:*:*:*:*

History

07 Nov 2023, 01:59

Type Values Removed Values Added
References
  • {'url': 'http://www.bb-pcsecurity.de/Websecurity/342/org/Sonium_Enterprise_Adressbook_Version_0.2_(folder)_RFI.htm', 'name': 'http://www.bb-pcsecurity.de/Websecurity/342/org/Sonium_Enterprise_Adressbook_Version_0.2_(folder)_RFI.htm', 'tags': [], 'refsource': 'MISC'}
  • () http://www.bb-pcsecurity.de/Websecurity/342/org/Sonium_Enterprise_Adressbook_Version_0.2_%28folder%29_RFI.htm -

Information

Published : 2006-08-23 19:04

Updated : 2024-02-28 10:42


NVD link : CVE-2006-4311

Mitre link : CVE-2006-4311

CVE.ORG link : CVE-2006-4311


JSON object : View

Products Affected

sonium

  • enterprise_adressbook