1246Third-party advisory
http://securityreason.com/securityalert/1246 CVE-2006-3689
Subberz Lite - UserFunc Remote File Inclusion
Record summary
CVE-2006-3689 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
PHP remote file inclusion vulnerability in user-func.php in Codeworks Gnomedia SubberZ[Lite] allows remote attackers to execute arbitrary PHP code via a URL in the myadmindir parameter. NOTE: this issue has been disputed by a third party that claims that " the myadmindir variable is set before any GET variables are processed.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSubberz Lite - UserFunc Remote File InclusionExploitDB exploitby Chironex FleckeriNot analyzed1 file
References
728592vdb entry
http://www.osvdb.org/28592 20060714 SubberZ[Lite] - Remote File Includemailing list
http://www.securityfocus.com/archive/1/440139/100/0/threaded 20060717 Re: SubberZ[Lite] - Remote File Includemailing list
http://www.securityfocus.com/archive/1/440864/100/100/threaded 18990vdb entry
http://www.securityfocus.com/bid/18990 subberzlite-userfunc-file-include(27748)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/27748 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-3689