Remote File Inclusion Vulnerabilities in Active PHP Bookmarks by L. Brandon Stone and Nathanial P. Hendler
CVE-2006-6167

Currently unrated

Key Information:

Vendor
CVE Published:
29 November 2006

What is CVE-2006-6167?

Active PHP Bookmarks version 1.1.02 is susceptible to multiple PHP remote file inclusion vulnerabilities. These weaknesses enable remote attackers to execute arbitrary PHP code by injecting a URL into the APB_SETTINGS['apb_path'] parameter, which is utilized in critical files such as apb_common.php and apb.php. Although there are discussions about the nature of the vulnerability and mitigation due to GPC variable considerations, the risk of potential exploitation remains significant.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.