CVE-2006-0786
Incomplete blacklist vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier, with allow_url_fopen enabled, allows remote attackers to conduct PHP remote file include attacks via a path parameter that specifies a (1) UNC share or (2) ftps URL, which bypasses the check for "http://", "ftp://", and "https://" URLs.
- Affected products
- Phpkit
- Phpkit
- ≤ 1.6.1
- Fix
- Available
- CVSS 2.0
- 5.1 MEDIUM
- EPSS
- 2.4% (82th percentile)
- NVD status
- Modified
- Published
- 2006-02-19
CVE-2006-0786 at NVD
1 known exploit for CVE-2006-0786
Proof-of-concept code and exploit modules indexed by Sploitus