ultiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute arbitrary PHP code via a URL in the g_documentRoot parameter to (1) Alias.php, (2) Article.php, (3) ArticleAttachment.php, (4) ArticleComment.php, (5) ArticleData.php, (6) ArticleImage.php, (7) ArticleIndex.php, (8) ArticlePublish.php, (9) ArticleTopic.php, (10) ArticleType.php, (11) ArticleTypeField.php, (12) Attachment.php, (13) Country.php, (14) DatabaseObject.php, (15) Event.php, (16) IPAccess.php, (17) Image.php, (18) Issue.php, (19) IssuePublish.php, (20) Language.php, (21) Log.php, (22) LoginAttempts.php, (23) Publication.php, (24) Section.php, (25) ShortURL.php, (26) Subscription.php, (27) SubscriptionDefaultTime.php, (28) SubscriptionSection.php, (29) SystemPref.php, (30) Template.php, (31) TimeUnit.php, (32) Topic.php, (33) UrlType.php, (34) User.php, and (35) UserType.php in implementation/management/classes/; (36) configuration.php and (37) db_connect.php in implementation/management/; and (38) LocalizerConfig.php and (39) LocalizerLanguage.php in implementation/management/priv/localizer/.
Configuration 1 (hide)
|
21 Nov 2024, 00:21
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://code.campware.org/projects/campsite/changeset/6057 - Patch | |
| References | () http://code.campware.org/projects/campsite/changeset/6058 - Patch | |
| References | () http://code.campware.org/projects/campsite/query?milestone=2.6.2 - | |
| References | () http://code.campware.org/projects/campsite/ticket/2349 - | |
| References | () http://sourceforge.net/project/shownotes.php?release_id=459574&group_id=66936 - Patch | |
| References | () http://www.osvdb.org/34187 - | |
| References | () http://www.osvdb.org/34188 - | |
| References | () http://www.osvdb.org/34189 - | |
| References | () http://www.osvdb.org/34190 - | |
| References | () http://www.osvdb.org/34191 - | |
| References | () http://www.osvdb.org/34192 - | |
| References | () http://www.osvdb.org/34193 - | |
| References | () http://www.osvdb.org/34194 - | |
| References | () http://www.osvdb.org/34195 - | |
| References | () http://www.osvdb.org/34196 - | |
| References | () http://www.osvdb.org/34197 - | |
| References | () http://www.osvdb.org/34198 - | |
| References | () http://www.osvdb.org/34199 - | |
| References | () http://www.osvdb.org/34200 - | |
| References | () http://www.osvdb.org/34201 - | |
| References | () http://www.osvdb.org/34202 - | |
| References | () http://www.osvdb.org/34203 - | |
| References | () http://www.osvdb.org/34204 - | |
| References | () http://www.osvdb.org/34205 - | |
| References | () http://www.osvdb.org/34206 - | |
| References | () http://www.osvdb.org/34207 - | |
| References | () http://www.osvdb.org/34208 - | |
| References | () http://www.osvdb.org/34209 - | |
| References | () http://www.osvdb.org/34210 - | |
| References | () http://www.osvdb.org/34211 - | |
| References | () http://www.osvdb.org/34212 - | |
| References | () http://www.osvdb.org/34213 - | |
| References | () http://www.osvdb.org/34214 - | |
| References | () http://www.osvdb.org/34215 - | |
| References | () http://www.osvdb.org/34216 - | |
| References | () http://www.osvdb.org/34217 - | |
| References | () http://www.osvdb.org/34218 - | |
| References | () http://www.osvdb.org/34219 - | |
| References | () http://www.osvdb.org/34220 - | |
| References | () http://www.osvdb.org/34221 - | |
| References | () http://www.osvdb.org/34222 - | |
| References | () http://www.osvdb.org/34223 - | |
| References | () http://www.osvdb.org/34224 - | |
| References | () http://www.osvdb.org/34225 - | |
| References | () http://www.securityfocus.com/bid/23874 - |
Published : 2006-11-15 15:07
Updated : 2025-04-09 00:30
NVD link : CVE-2006-5911
Mitre link : CVE-2006-5911
CVE.ORG link : CVE-2006-5911
JSON object : View