This application requires Javascript for optimal performance.

Knusperleicht.ShoutBox.Remote.File.Inclusion

Release Date

Jan 18, 2007

Severity

low

Impact

Compromise of the affected system.

Description

It indicates a possible exploit of a file inclusion vulnerability in Knusperleicht Shoutbox 4.4 and earlier, that may allow remote attackers to execute arbitrary PHP code via a URL in the sb_include_path parameter.

Affected Products

Knusperleicht ShoutBox 4.4

Recommended Actions

Currently we are not aware of any vendor-supplied patches for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-3989

Reference/s

http://www.securityfocus.com/bid/19273 (BugTraq)
http://www.milw0rm.com/exploits/2103

Reference: VID-13839