Multiple PHP remote file inclusion vulnerabilities in Patrick Michaelis Wili-CMS allow remote attackers to execute arbitrary PHP code via a URL in the globals[content_dir] parameter in (1) example-view/templates/article.php, (2) example-view/templates/root.php, and (3) example-view/templates/dates_list.php.
References
Configurations
History
21 Nov 2024, 00:17
Type | Values Removed | Values Added |
---|---|---|
References | () http://securityreason.com/securityalert/1633 - | |
References | () http://www.securityfocus.com/archive/1/446575/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/20134 - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/29101 - |
Information
Published : 2006-09-26 02:07
Updated : 2025-04-03 01:03
NVD link : CVE-2006-4987
Mitre link : CVE-2006-4987
CVE.ORG link : CVE-2006-4987
JSON object : View
Products Affected
patrick_michaelis
- wili-cms
CWE