Remote File Inclusion Vulnerabilities in Free File Hosting by Free Image Hosting
CVE-2006-5763

Currently unrated

Key Information:

Vendor
CVE Published:
6 November 2006

What is CVE-2006-5763?

Multiple PHP remote file inclusion vulnerabilities exist in Free File Hosting 1.1, and potentially earlier versions, specifically when the register_globals setting is enabled. These flaws permit unauthorized remote attackers to execute arbitrary PHP code through a URL input in the AD_BODY_TEMP parameter, targeting scripts such as login.php, register.php, and send.php. This vulnerability also extends to the File Upload System, which is integrated into Free File Hosting, and is similarly present in Free Image Hosting 2.0. Attackers can exploit this weakness to gain control over the affected server.

References

EPSS Score

11% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.