CVE Vulnerabilities

CVE-2006-0881

Published: Feb 24, 2006 | Modified: Oct 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noahs Classifieds 1.3, when register_globals is enabled, allow remote attackers to include arbitrary PHP files via the (1) upperTemplate and (2) lowerTemplate parameters, as demonstrated using the lowerTemplate parameter to index.php.

Affected Software

Name Vendor Start Version End Version
Noahs_classifieds Phpoutsourcing 1.2 (including) 1.2 (including)
Noahs_classifieds Phpoutsourcing 1.3 (including) 1.3 (including)

References