Multiple PHP remote file inclusion vulnerabilities in MangoBery CMS 0.5.5 allow remote attackers to execute arbitrary PHP code via a URL in the Site_Path parameter to (1) boxes/quotes.php or (2) templates/mangobery/footer.sample.php.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/3598 | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/33290 | vdb entry |
http://www.vupen.com/english/advisories/2007/1147 | vdb entry |
http://secunia.com/advisories/24686 | exploit third party advisory vendor advisory |
http://www.securityfocus.com/bid/23187 | vdb entry |
http://osvdb.org/34510 | vdb entry |
http://mangobery.svn.sourceforge.net/viewvc/mangobery?view=rev&revision=70 | patch |
http://osvdb.org/34509 | vdb entry |