19923Third-party advisory
http://secunia.com/advisories/19923 CVE-2006-2175
Fast Click 1.1.3/2.3.8 - 'show.php' Remote File Inclusion
Record summary
CVE-2006-2175 has a selected CVSS score of 6.4; EIP currently links 1 catalogued exploit.
Description
PHP remote file inclusion vulnerability in FtrainSoft Fast Click 2.3.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) show.php or (2) top.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFast Click 1.1.3/2.3.8 - 'show.php' Remote File InclusionExploitDB exploitby R@1D3NNot analyzed1 file
References
111016021vdb entry
http://securitytracker.com/id?1016021 aria-security.net
http://www.aria-security.net/advisory/fc/fastclick.txt 25192vdb entry
http://www.osvdb.org/25192 25289vdb entry
http://www.osvdb.org/25289 20060502 Fast Click <= 2.3.8 Remote File Inclusionmailing list
http://www.securityfocus.com/archive/1/432963/100/0/threaded 17813vdb entry
http://www.securityfocus.com/bid/17813 ADV-2006-1631vdb entry
http://www.vupen.com/english/advisories/2006/1631 fastclick-multiple-file-include(26235)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/26235 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-2175 1740exploit
https://www.exploit-db.com/exploits/1740