CVE-2006-5494

Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB module for PHP-Nuke allow remote attackers to execute arbitrary PHP code via a URL in the (1) adminpath or (2) basepath parameters. NOTE: this issue might overlap CVE-2006-6795.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpnuke:php-nuke:8.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2006-10-25 10:07

Updated : 2023-12-10 10:40


NVD link : CVE-2006-5494

Mitre link : CVE-2006-5494

CVE.ORG link : CVE-2006-5494


JSON object : View

Products Affected

phpnuke

  • php-nuke
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')