PHP remote file inclusion vulnerability in common.php in Intensive Point...
Vulnerability Description
PHP remote file inclusion vulnerability in common.php in Intensive Point iUser Ecommerce allows remote attackers to include arbitrary files via a URL in the include_path variable, which is not initialized before being used.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-0854
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.osvdb.org/23429
- http://www.securityfocus.com/bid/16787
- http://www.xorcrew.net/xpa/XPA-iUser.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24724
- http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0339.html
- http://www.vupen.com/english/advisories/2006/0699
- http://secunia.com/advisories/18903
Affected Vendor
intensive point
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.