22885Third-party advisory
http://secunia.com/advisories/22885 CVE-2006-6047
Etomite CMS 0.6.1.2 - '/manager/index.php' Local File Inclusion
Record summary
CVE-2006-6047 has a selected CVSS score of 5.8; EIP currently links 1 catalogued exploit.
Description
Directory traversal vulnerability in manager/index.php in Etomite 0.6.1.2 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the f parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBEtomite CMS 0.6.1.2 - '/manager/index.php' Local File InclusionExploitDB exploitby RevengeNot analyzed1 file
References
100xcafebabe.it
http://www.0xcafebabe.it/sploits/etm_0612_remote_com.pl etomite.org
http://www.etomite.org/forums/index.php?showtopic=6388 20061116 Etomite CMS 0.6.1.2 Multiple Vulnerabilities ( Sql Injection + Local file inclusion )mailing list
http://www.securityfocus.com/archive/1/451838/100/0/threaded 20061117 Re: Etomite CMS 0.6.1.2 Multiple Vulnerabilities ( Sql Injection + Local file inclusion )mailing list
http://www.securityfocus.com/archive/1/451930/100/0/threaded 21135vdb entry
http://www.securityfocus.com/bid/21135 ADV-2006-4558vdb entry
http://www.vupen.com/english/advisories/2006/4558 etomite-index-file-include(30329)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/30329 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-6047 2790exploit
https://www.exploit-db.com/exploits/2790