CVE-2006-4990

Multiple PHP remote file inclusion vulnerabilities in PhotoPost allow remote attackers to execute arbitrary PHP code via a URL in the PP_PATH parameter in (1) addfav.php, (2) adm-admlog.php, (3) adm-approve.php, (4) adm-backup.php, (5) adm-cats.php, (6) adm-cinc.php, (7) adm-db.php, (8) adm-editcfg.php, (9) adm-inc.php, (10) adm-index.php, (11) adm-modcom.php, (12) adm-move.php, (13) adm-options.php, (14) adm-order.php, (15) adm-pa.php, (16) adm-photo.php, (17) adm-purge.php, (18) adm-style.php, (19) adm-templ.php, (20) adm-userg.php, (21) adm-users.php, (22) bulkupload.php, (23) cookies.php, (24) comments.php, (25) ecard.php, (26) editphoto.php, (27) register.php, (28) showgallery.php, (29) showmembers.php, (30) useralbums.php, (31) uploadphoto.php, (32) search.php, or (33) adm-menu.php, different vectors than CVE-2006-4828.
References
Link Resource
http://securityreason.com/securityalert/1632
http://www.osvdb.org/32221
http://www.osvdb.org/32222
http://www.osvdb.org/32223
http://www.osvdb.org/32224
http://www.osvdb.org/32225
http://www.osvdb.org/32226
http://www.osvdb.org/32227
http://www.osvdb.org/32228
http://www.osvdb.org/32229
http://www.osvdb.org/32230
http://www.osvdb.org/32231
http://www.osvdb.org/32232
http://www.osvdb.org/32233
http://www.osvdb.org/32234
http://www.osvdb.org/32235
http://www.osvdb.org/32236
http://www.osvdb.org/32237
http://www.osvdb.org/32238
http://www.osvdb.org/32239
http://www.osvdb.org/32240
http://www.osvdb.org/32243
http://www.osvdb.org/32245
http://www.osvdb.org/32246
http://www.osvdb.org/32247
http://www.osvdb.org/32248
http://www.osvdb.org/32249
http://www.osvdb.org/32250
http://www.osvdb.org/32251
http://www.osvdb.org/32252
http://www.osvdb.org/32253
http://www.securityfocus.com/archive/1/446224/100/0/threaded
http://securityreason.com/securityalert/1632
http://www.osvdb.org/32221
http://www.osvdb.org/32222
http://www.osvdb.org/32223
http://www.osvdb.org/32224
http://www.osvdb.org/32225
http://www.osvdb.org/32226
http://www.osvdb.org/32227
http://www.osvdb.org/32228
http://www.osvdb.org/32229
http://www.osvdb.org/32230
http://www.osvdb.org/32231
http://www.osvdb.org/32232
http://www.osvdb.org/32233
http://www.osvdb.org/32234
http://www.osvdb.org/32235
http://www.osvdb.org/32236
http://www.osvdb.org/32237
http://www.osvdb.org/32238
http://www.osvdb.org/32239
http://www.osvdb.org/32240
http://www.osvdb.org/32243
http://www.osvdb.org/32245
http://www.osvdb.org/32246
http://www.osvdb.org/32247
http://www.osvdb.org/32248
http://www.osvdb.org/32249
http://www.osvdb.org/32250
http://www.osvdb.org/32251
http://www.osvdb.org/32252
http://www.osvdb.org/32253
http://www.securityfocus.com/archive/1/446224/100/0/threaded
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:photopost:photopost_php_pro:4.5:*:*:*:*:*:*:*
cpe:2.3:a:photopost:photopost_php_pro:4.6:*:*:*:*:*:*:*

History

21 Nov 2024, 00:17

Type Values Removed Values Added
References () http://securityreason.com/securityalert/1632 - () http://securityreason.com/securityalert/1632 -
References () http://www.osvdb.org/32221 - () http://www.osvdb.org/32221 -
References () http://www.osvdb.org/32222 - () http://www.osvdb.org/32222 -
References () http://www.osvdb.org/32223 - () http://www.osvdb.org/32223 -
References () http://www.osvdb.org/32224 - () http://www.osvdb.org/32224 -
References () http://www.osvdb.org/32225 - () http://www.osvdb.org/32225 -
References () http://www.osvdb.org/32226 - () http://www.osvdb.org/32226 -
References () http://www.osvdb.org/32227 - () http://www.osvdb.org/32227 -
References () http://www.osvdb.org/32228 - () http://www.osvdb.org/32228 -
References () http://www.osvdb.org/32229 - () http://www.osvdb.org/32229 -
References () http://www.osvdb.org/32230 - () http://www.osvdb.org/32230 -
References () http://www.osvdb.org/32231 - () http://www.osvdb.org/32231 -
References () http://www.osvdb.org/32232 - () http://www.osvdb.org/32232 -
References () http://www.osvdb.org/32233 - () http://www.osvdb.org/32233 -
References () http://www.osvdb.org/32234 - () http://www.osvdb.org/32234 -
References () http://www.osvdb.org/32235 - () http://www.osvdb.org/32235 -
References () http://www.osvdb.org/32236 - () http://www.osvdb.org/32236 -
References () http://www.osvdb.org/32237 - () http://www.osvdb.org/32237 -
References () http://www.osvdb.org/32238 - () http://www.osvdb.org/32238 -
References () http://www.osvdb.org/32239 - () http://www.osvdb.org/32239 -
References () http://www.osvdb.org/32240 - () http://www.osvdb.org/32240 -
References () http://www.osvdb.org/32243 - () http://www.osvdb.org/32243 -
References () http://www.osvdb.org/32245 - () http://www.osvdb.org/32245 -
References () http://www.osvdb.org/32246 - () http://www.osvdb.org/32246 -
References () http://www.osvdb.org/32247 - () http://www.osvdb.org/32247 -
References () http://www.osvdb.org/32248 - () http://www.osvdb.org/32248 -
References () http://www.osvdb.org/32249 - () http://www.osvdb.org/32249 -
References () http://www.osvdb.org/32250 - () http://www.osvdb.org/32250 -
References () http://www.osvdb.org/32251 - () http://www.osvdb.org/32251 -
References () http://www.osvdb.org/32252 - () http://www.osvdb.org/32252 -
References () http://www.osvdb.org/32253 - () http://www.osvdb.org/32253 -
References () http://www.securityfocus.com/archive/1/446224/100/0/threaded - () http://www.securityfocus.com/archive/1/446224/100/0/threaded -

Information

Published : 2006-09-26 02:07

Updated : 2024-11-21 00:17


NVD link : CVE-2006-4990

Mitre link : CVE-2006-4990

CVE.ORG link : CVE-2006-4990


JSON object : View

Products Affected

photopost

  • photopost_php_pro