CVE-2006-5762
CVE-2006-5762
PHP remote file inclusion vulnerability in forgot_pass.php in Free File Hosting 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. NOTE: this issue was later reported for the "File Upload System" which is a component of Free File Hosting. This also affects Free Image Hosting 2.0, which contains the same code.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/3568unverifiedcve_referencewww.exploit-db.com/exploits/2670unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://secunia.com/advisories/22594https://exchange.xforce.ibmcloud.com/vulnerabilities/29874https://exchange.xforce.ibmcloud.com/vulnerabilities/33196https://www.exploit-db.com/exploits/2670https://www.exploit-db.com/exploits/3568http://www.attrition.org/pipermail/vim/2007-March/001473.htmlhttp://www.osvdb.org/30143http://www.rahim.webd.pl/exploity/Exploits/111.txthttp://www.securityfocus.com/archive/1/463707/100/0/threadedhttp://www.securityfocus.com/bid/20781http://www.securityfocus.com/bid/23118http://www.vupen.com/english/advisories/2006/4228