| ID | CVE-2006-2881 | ||||||
| Sažetak | Multiple PHP remote file inclusion vulnerabilities in DreamAccount 3.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the da_path parameter in the (1) auth.cookie.inc.php, (2) auth.header.inc.php, or (3) auth.sessions.inc.php scripts. | ||||||
| Reference |
|
||||||
| CVSS |
|
||||||
| Pristup |
|
||||||
| Impact |
|
||||||
| CVSS vektor | AV:N/AC:H/Au:N/C:P/I:P/A:P | ||||||
| Zadnje važnije ažuriranje | 18-10-2018 - 16:43 | ||||||
| Objavljeno | 07-06-2006 - 10:02 |

