Remote File Inclusion Vulnerabilities in Active PHP Bookmarks by L. Brandon Stone and Nathanial P. Hendler
CVE-2006-6167
Currently unrated
What is CVE-2006-6167?
Active PHP Bookmarks version 1.1.02 is susceptible to multiple PHP remote file inclusion vulnerabilities. These weaknesses enable remote attackers to execute arbitrary PHP code by injecting a URL into the APB_SETTINGS['apb_path'] parameter, which is utilized in critical files such as apb_common.php and apb.php. Although there are discussions about the nature of the vulnerability and mitigation due to GPC variable considerations, the risk of potential exploitation remains significant.
