CVE Vulnerabilities

CVE-2006-3998

Published: Aug 05, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

PHP remote file inclusion vulnerability in conf.php in WoWRoster (aka World of Warcraft Roster) 1.5.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the subdir parameter.

Affected Software

NameVendorStart VersionEnd Version
WowrosterWowroster1.5 (including)1.5 (including)
WowrosterWowroster1.5.1 (including)1.5.1 (including)

References