CVE Vulnerabilities

CVE-2006-4945

Published: Sep 23, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Multiple PHP remote file inclusion vulnerabilities in Cardway (aka Frederic Boudaud) DigitalWebShop 1.128 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _PHPLIB[libdir] parameter to (1) rechnung.php or (2) prepend.php.

Affected Software

NameVendorStart VersionEnd Version
DigitalwebshopCardway1.110 (including)1.110 (including)
DigitalwebshopCardway1.120 (including)1.120 (including)
DigitalwebshopCardway1.128 (including)1.128 (including)

References