CVE-2006-5318

PHP remote file inclusion vulnerability in index.php in Nayco JASmine (aka Jasmine-Web) allows remote attackers to execute arbitrary PHP code via an FTP URL in the section parameter.

Score7.5
Access VectorNETWORK
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactPARTIAL
Availability ImpactPARTIAL
Published2006-10-17 01:07:00.000-04
Last Modified2018-10-17 05:42:09.000-04

Vulnerable Software List

VendorProductVersions
Nayco Jasmine

References

SourceLink
MISChttp://acid-root.new.fr/poc/13061007.txt
BUGTRAQ20061007 7 php scripts File Inclusion / Source disclosure Vuln
BID20430
VUPENADV-2006-4007
XFjasmine-index-file-include(29423)
EXPLOIT-DB2505