Executive Summary

Informations
Name CVE-2006-4914 First vendor Publication 2006-09-20
Vendor Cve Last vendor Modification 2024-11-21

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:H/Au:N/C:P/I:N/A:N)
Cvss Base Score 2.6 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity High
Cvss Expoit Score 4.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Directory traversal vulnerability in A.l-Pifou 1.8p2 allows remote attackers to read arbitrary files via ".." sequences in the ze_langue_02 cookie, as demonstrated by using the choix_lng parameter to choix_langue.php to indirectly set the cookie, then accessing livre_dor.php to trigger the inclusion from inc/change_lang_ck.php, possibly related to livre_livre.php. NOTE: the livre_livre.php relationship has been reported by some third party sources.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4914

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1

Open Source Vulnerability Database (OSVDB)

Id Description
29014 A.l-Pifou livre_lire.php ze_langue_02 Cookie Parameter Local File Inclusion

A.l-Pifou contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to livre_lire.php not properly sanitizing user input supplied to the 'e_langue_02' cookie variable. This may allow an attacker to include a file from a local host that contains arbitrary commands which will be executed by the vulnerable script.

Sources (Detail)

http://seclists.org/fulldisclosure/2006/Sep/0341.html
http://secunia.com/advisories/22038
http://www.osvdb.org/29014
http://www.securityfocus.com/bid/20120
http://www.vupen.com/english/advisories/2006/3707
https://exchange.xforce.ibmcloud.com/vulnerabilities/29050
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
Date Informations
2024-11-28 23:19:27
  • Multiple Updates
2024-11-28 12:10:05
  • Multiple Updates
2021-05-04 12:04:36
  • Multiple Updates
2021-04-22 01:05:15
  • Multiple Updates
2020-05-23 00:18:26
  • Multiple Updates
2017-07-20 09:23:54
  • Multiple Updates
2016-06-28 15:57:54
  • Multiple Updates
2016-04-26 15:06:38
  • Multiple Updates
2013-05-11 11:09:54
  • Multiple Updates