PT-2006-5441 · Web Provence+1 · Web Provence Sl Site+1

Kw3[R]Ln

·

Published

2006-09-09

·

Updated

2018-10-17

·

CVE-2006-4656

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Web Provence SL Site versions 1.0 and earlier
Description A remote file inclusion issue exists, allowing remote attackers to execute arbitrary PHP code via a URL in the spaw root parameter. This issue is actually in a third-party product, SPAW Editor PHP Edition.
Recommendations For Web Provence SL Site versions 1.0 and earlier, consider disabling the spaw control.class.php file in the admin/editeur directory until a patch is available. Restrict access to the spaw root parameter to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4656

Affected Products

Spaw Editor Php Edition
Web Provence Sl Site