CVE

CVE-2006-6856

Severity:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/12/2006
Last modified:
19/10/2017

Description

Direct static code injection vulnerability in WebText CMS 0.4.5.2 and earlier allows remote attackers to inject arbitrary PHP code into a script in wt/users/ via the im parameter during a profile edit (edycja) operation, which is then executed via a direct request for this script.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:webtext:webtext:*:*:*:*:*:*:*:* 0.4.5.2 (including)