CVE Vulnerabilities

CVE-2006-4945

Published: Sep 23, 2006 | Modified: Oct 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple PHP remote file inclusion vulnerabilities in Cardway (aka Frederic Boudaud) DigitalWebShop 1.128 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _PHPLIB[libdir] parameter to (1) rechnung.php or (2) prepend.php.

Affected Software

Name Vendor Start Version End Version
Digitalwebshop Cardway 1.110 (including) 1.110 (including)
Digitalwebshop Cardway 1.120 (including) 1.120 (including)
Digitalwebshop Cardway 1.128 (including) 1.128 (including)

References