Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.4.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _AMGconfig[cfg_serverpath] parameter in (1) modules/AllMyGuests/signin.php (aka the Nuke module) and (2) AllMyGuests/signin.php (aka the standalone).
References
Link | Resource |
---|---|
http://secunia.com/advisories/22095 | Broken Link |
http://www.securityfocus.com/bid/20303 | Third Party Advisory VDB Entry |
http://www.vupen.com/english/advisories/2006/3863 | Permissions Required |
https://exchange.xforce.ibmcloud.com/vulnerabilities/29064 | VDB Entry |
https://www.exploit-db.com/exploits/2405 | Third Party Advisory VDB Entry |
http://secunia.com/advisories/22095 | Broken Link |
http://www.securityfocus.com/bid/20303 | Third Party Advisory VDB Entry |
http://www.vupen.com/english/advisories/2006/3863 | Permissions Required |
https://exchange.xforce.ibmcloud.com/vulnerabilities/29064 | VDB Entry |
https://www.exploit-db.com/exploits/2405 | Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 00:17
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/22095 - Broken Link | |
References | () http://www.securityfocus.com/bid/20303 - Third Party Advisory, VDB Entry | |
References | () http://www.vupen.com/english/advisories/2006/3863 - Permissions Required | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/29064 - VDB Entry | |
References | () https://www.exploit-db.com/exploits/2405 - Third Party Advisory, VDB Entry |
23 Apr 2024, 19:52
Type | Values Removed | Values Added |
---|---|---|
First Time |
Allmyguests Project
Allmyguests Project allmyguests |
|
References | () http://secunia.com/advisories/22095 - Broken Link | |
References | () http://www.securityfocus.com/bid/20303 - Third Party Advisory, VDB Entry | |
References | () http://www.vupen.com/english/advisories/2006/3863 - Permissions Required | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/29064 - VDB Entry | |
References | () https://www.exploit-db.com/exploits/2405 - Third Party Advisory, VDB Entry | |
CPE | cpe:2.3:a:allmyguests_project:allmyguests:*:*:*:*:*:*:*:* |
Information
Published : 2006-09-26 02:07
Updated : 2024-11-21 00:17
NVD link : CVE-2006-4993
Mitre link : CVE-2006-4993
CVE.ORG link : CVE-2006-4993
JSON object : View
Products Affected
allmyguests_project
- allmyguests
CWE