CVE Vulnerabilities

CVE-2006-0881

Published: Feb 24, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noahs Classifieds 1.3, when register_globals is enabled, allow remote attackers to include arbitrary PHP files via the (1) upperTemplate and (2) lowerTemplate parameters, as demonstrated using the lowerTemplate parameter to index.php.

Affected Software

NameVendorStart VersionEnd Version
Noahs_classifiedsPhpoutsourcing1.2 (including)1.2 (including)
Noahs_classifiedsPhpoutsourcing1.3 (including)1.3 (including)

References