Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by lang.php.
References
Configurations
History
21 Nov 2024, 00:20
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/22847 - Vendor Advisory | |
References | () http://www.rahim.webd.pl/exploit127.html - Exploit | |
References | () http://www.securityfocus.com/bid/21009 - Exploit | |
References | () http://www.vupen.com/english/advisories/2006/4473 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/30183 - | |
References | () https://www.exploit-db.com/exploits/2760 - |
Information
Published : 2006-11-14 22:07
Updated : 2025-04-09 00:30
NVD link : CVE-2006-5894
Mitre link : CVE-2006-5894
CVE.ORG link : CVE-2006-5894
JSON object : View
Products Affected
rama_cms
- rama_cms
CWE