CVE Vulnerabilities

CVE-2006-4594

Published: Sep 06, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpAtm) 1.21 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the include_location parameter in (1) confirm.php or (2) login.php. NOTE: the include_location parameter to index.php is already covered by CVE-2005-1681.

Affected Software

NameVendorStart VersionEnd Version
Php_advanced_transfer_managerBugada_andrea*1.21 (including)
Php_advanced_transfer_managerBugada_andrea1.20 (including)1.20 (including)

References