PHP remote file inclusion vulnerability in resources/includes/popp.config.loader.inc.php in PopSoft Digital...
Vulnerability Description
PHP remote file inclusion vulnerability in resources/includes/popp.config.loader.inc.php in PopSoft Digital PopPhoto Studio 3.5.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter (cfg['popphoto_base_path'] variable). NOTE: Pixaria has notified CVE that "PopPhoto is NOT a product of Pixaria. It was a product of PopSoft Digital and is only hosted by Pixaria as a courtesy... The vulnerability listed was patched by the previous vendor and all previous users have received this update."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-2395
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/17970
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26449
- http://www.attrition.org/pipermail/vim/2006-June/000869.html
- http://securitytracker.com/id?1016092
- http://www.pixaria.com/news/article/35/
- http://www.vupen.com/english/advisories/2006/1792
- http://secunia.com/advisories/20087
- http://www.osvdb.org/25524
- http://pridels0.blogspot.com/2006/05/popphoto-remote-file-inclusion-vuln.html
Affected Vendor
popsoft digital
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.