PT-2006-2772 · Circle R · Circle R Monster Top List

Fluffy_Bunny

·

Published

2006-04-13

·

Updated

2017-10-11

·

CVE-2006-1781

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Circle R Monster Top List (MTL) versions 1.4 through 1.4.2
Description A remote file inclusion issue allows attackers to execute arbitrary PHP code via a URL in the root path parameter in the functions.php file.
Recommendations For Circle R Monster Top List (MTL) versions 1.4 through 1.4.2, consider restricting access to the root path parameter in the functions.php file until a patch is available. Avoid using the root path parameter with untrusted input to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-1781

Affected Products

Circle R Monster Top List