CVE-2006-4962
CVE-2006-4962
Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read and execute arbitrary local files via a .. (dot dot) sequence via the phpExt parameter, as demonstrated by executing PHP code in a log file.
Productos afectados
n/a · n/aPoCs públicas encontradas — 2
cve_referencewww.exploit-db.com/exploits/2402no verificadocve_referencewww.exploit-db.com/exploits/4277no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://secunia.com/advisories/22031https://exchange.xforce.ibmcloud.com/vulnerabilities/29067https://www.exploit-db.com/exploits/2402https://www.exploit-db.com/exploits/4277http://www.securityfocus.com/bid/20123http://www.securityfocus.com/bid/25264http://www.vupen.com/english/advisories/2006/3736