PHP remote file inclusion vulnerability in micro_cms_files/microcms-include.php in Implied By Design (IBD) Micro CMS 3.5 (aka 0.3.5) and earlier allows remote attackers to execute arbitrary PHP code via a URL in the microcms_path parameter. NOTE: it was later reported that this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2006-06-22T22:00:00
Updated: 2024-08-07T18:16:06.150Z
Reserved: 2006-06-22T00:00:00
Link: CVE-2006-3144

No data.

Status : Deferred
Published: 2006-06-22T22:06:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2006-3144

No data.