BasiliX 多个PHP远程文件包含漏洞 CVE-2006-5167 CNNVD-200610-064

5.1 AV AC AU C I A
发布: 2006-10-05
修订: 2017-10-19

BasiliX中存在多个PHP远程文件包含漏洞。远程攻击者通过以下方式执行任意PHP代码: /files/下脚本中的(1)BSX_LIBDIR参数内的URL,这些脚本包括:(a) abook.php3, (b) compose-attach.php3, (c) compose-menu.php3, (d) compose-new.php3, (e) compose-send.php3, (f) folder-create.php3, (g) folder-delete.php3, (h) folder-empty.php3, (i) folder-rename.php3, (j) folders.php3, (k) mbox-action.php3, (l) mbox-list.php3, (m) message-delete.php3, (n) message-forward.php3, (o) message-header.php3, (p) message-print.php3, (q) message-read.php3, (r) message-reply.php3, (s) message-replyall.php3, (t) message-search.php3或(u) settings.php3;以及(v) files/login.php3的(2) BSX_HTXDIR参数中的URL。

0%
当前有1条漏洞利用/PoC
当前有5条受影响产品信息