Remote File Inclusion Vulnerabilities in Free File Hosting by Free Image Hosting
CVE-2006-5763
Currently unrated
What is CVE-2006-5763?
Multiple PHP remote file inclusion vulnerabilities exist in Free File Hosting 1.1, and potentially earlier versions, specifically when the register_globals setting is enabled. These flaws permit unauthorized remote attackers to execute arbitrary PHP code through a URL input in the AD_BODY_TEMP parameter, targeting scripts such as login.php, register.php, and send.php. This vulnerability also extends to the File Upload System, which is integrated into Free File Hosting, and is similarly present in Free Image Hosting 2.0. Attackers can exploit this weakness to gain control over the affected server.
References
EPSS Score
11% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved