Multiple PHP remote file inclusion vulnerabilities in Plume CMS 1.0.6...
Vulnerability Description
Multiple PHP remote file inclusion vulnerabilities in Plume CMS 1.0.6 and earlier allow remote attackers to execute arbitrary PHP code via the _PX_config[manager_path] parameter to (1) articles.php, (2) categories.php, (3) news.php, (4) prefs.php, (5) sites.php, (6) subtypes.php, (7) users.php, (8) xmedia.php, (9) frontinc/class.template.php, (10) inc/lib.text.php, (11) install/index.php, (12) install/upgrade.php, and (13) tools/htaccess/index.php. NOTE: other vectors are covered by CVE-2006-3562, CVE-2006-2645, and CVE-2006-0725.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-4533
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.osvdb.org/31179
- http://www.osvdb.org/31172
- http://www.osvdb.org/31177
- http://www.osvdb.org/31180
- http://www.osvdb.org/31171
- http://www.osvdb.org/31183
- http://www.osvdb.org/31175
- http://www.osvdb.org/31181
- http://www.securityfocus.com/bid/19629
- http://www.osvdb.org/31176
- http://www.osvdb.org/31178
- http://www.osvdb.org/31174
- http://packetstormsecurity.org/0608-exploits/plume-1.0.6.txt
- http://www.osvdb.org/31173
- http://www.osvdb.org/31182
More from plume-cms
View All →Affected Vendor
plume-cms
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.