Multiple PHP remote file inclusion vulnerabilities in Dmitry Sheiko Business Card Web Builder (BCWB) 2.5 allow remote attackers to execute arbitrary PHP code via a URL in the root_path_admin parameter to (1) /include/startup.inc.php, (2) dcontent/default.css.php, or (3) system/default.css.php, different vectors than CVE-2006-4946.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/29905 | vdb entry |
http://www.securityfocus.com/archive/1/450069/100/100/threaded | mailing list |
http://securityreason.com/securityalert/1836 | third party advisory |