CVE-2006-5506

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
25/10/2006
Last modified:
19/10/2017

Description

Multiple PHP remote file inclusion vulnerabilities in WiClear 0.10 allow remote attackers to execute arbitrary PHP code via the path parameter in (1) inc/prepend.inc.php, (2) inc/lib/boxes.lib.php, (3) inc/lib/tools.lib.php, (4) tools/trackback/index.php, and (5) tools/utf8conversion/index.php in admin/; and (6) prepend.inc.php, (7) lib/boxes.lib.php, and (8) lib/history.lib.php in inc/.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wiclear:wiclear:0.10:*:*:*:*:*:*:*