2363Third-party advisory
http://securityreason.com/securityalert/2363 CVE-2006-7104
Mambo Module MOStlyCE 4.5.4 - 'HTMLTemplate.php' Remote File Inclusion
Record summary
CVE-2006-7104 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
PHP remote file inclusion vulnerability in htmltemplate.php in the Chad Auld MOStlyContent Editor (MOStlyCE) as created on May 2006, a component for Mambo 4.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMambo Module MOStlyCE 4.5.4 - 'HTMLTemplate.php' Remote File InclusionExploitDB exploitby The_BeKiRNot analyzed1 file
References
520061015 MOStlyCEV454 - Remote File Include Vulnerabilitiesmailing list
http://www.securityfocus.com/archive/1/448786 20549vdb entry
http://www.securityfocus.com/bid/20549 mostlycev-htmltemplate-file-include(29598)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/29598 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-7104