PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[AA_INC_PATH] parameter in (1) cached.php3, (2) cron.php3, (3) discussion.php3, (4) filldisc.php3, (5) filler.php3, (6) fillform.php3, (7) go.php3, (8) hiercons.php3, (9) jsview.php3, (10) live_checkbox.php3, (11) offline.php3, (12) post2shtml.php3, (13) search.php3, (14) slice.php3, (15) sql_update.php3, (16) view.php3, (17) multiple files in the (18) admin/ folder, (19) includes folder, and (20) modules/ folder.
References
Link Providers
http://secunia.com/advisories/20299 cve-icon cve-icon
http://www.osvdb.org/27253 cve-icon cve-icon
http://www.osvdb.org/27254 cve-icon cve-icon
http://www.osvdb.org/27256 cve-icon cve-icon
http://www.osvdb.org/27257 cve-icon cve-icon
http://www.osvdb.org/27258 cve-icon cve-icon
http://www.osvdb.org/27259 cve-icon cve-icon
http://www.osvdb.org/27260 cve-icon cve-icon
http://www.osvdb.org/27261 cve-icon cve-icon
http://www.osvdb.org/27262 cve-icon cve-icon
http://www.osvdb.org/27263 cve-icon cve-icon
http://www.osvdb.org/27264 cve-icon cve-icon
http://www.osvdb.org/27265 cve-icon cve-icon
http://www.osvdb.org/27266 cve-icon cve-icon
http://www.osvdb.org/27267 cve-icon cve-icon
http://www.osvdb.org/27268 cve-icon cve-icon
http://www.osvdb.org/27269 cve-icon cve-icon
http://www.osvdb.org/27270 cve-icon cve-icon
http://www.osvdb.org/27271 cve-icon cve-icon
http://www.osvdb.org/27272 cve-icon cve-icon
http://www.osvdb.org/27273 cve-icon cve-icon
http://www.osvdb.org/27274 cve-icon cve-icon
http://www.osvdb.org/27275 cve-icon cve-icon
http://www.osvdb.org/27276 cve-icon cve-icon
http://www.osvdb.org/27277 cve-icon cve-icon
http://www.osvdb.org/27278 cve-icon cve-icon
http://www.osvdb.org/27279 cve-icon cve-icon
http://www.osvdb.org/27280 cve-icon cve-icon
http://www.osvdb.org/27281 cve-icon cve-icon
http://www.osvdb.org/27282 cve-icon cve-icon
http://www.osvdb.org/27283 cve-icon cve-icon
http://www.osvdb.org/27284 cve-icon cve-icon
http://www.osvdb.org/27285 cve-icon cve-icon
http://www.osvdb.org/27286 cve-icon cve-icon
http://www.osvdb.org/27287 cve-icon cve-icon
http://www.osvdb.org/27288 cve-icon cve-icon
http://www.osvdb.org/27289 cve-icon cve-icon
http://www.osvdb.org/27290 cve-icon cve-icon
http://www.osvdb.org/27291 cve-icon cve-icon
http://www.osvdb.org/27292 cve-icon cve-icon
http://www.osvdb.org/27293 cve-icon cve-icon
http://www.osvdb.org/27294 cve-icon cve-icon
http://www.osvdb.org/27295 cve-icon cve-icon
http://www.osvdb.org/27296 cve-icon cve-icon
http://www.osvdb.org/27297 cve-icon cve-icon
http://www.osvdb.org/27298 cve-icon cve-icon
http://www.osvdb.org/27299 cve-icon cve-icon
http://www.osvdb.org/27300 cve-icon cve-icon
http://www.osvdb.org/27301 cve-icon cve-icon
http://www.osvdb.org/27302 cve-icon cve-icon
http://www.osvdb.org/27303 cve-icon cve-icon
http://www.osvdb.org/27304 cve-icon cve-icon
http://www.osvdb.org/27305 cve-icon cve-icon
http://www.osvdb.org/27306 cve-icon cve-icon
http://www.osvdb.org/27308 cve-icon cve-icon
http://www.osvdb.org/27309 cve-icon cve-icon
http://www.osvdb.org/27310 cve-icon cve-icon
http://www.securityfocus.com/bid/19133 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/1997 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/26776 cve-icon cve-icon
https://www.exploit-db.com/exploits/1829 cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2006-05-31T10:00:00

Updated: 2024-08-07T17:58:51.912Z

Reserved: 2006-05-30T00:00:00

Link: CVE-2006-2686

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2006-05-31T10:06:00.000

Modified: 2017-10-19T01:29:09.190

Link: CVE-2006-2686

cve-icon Redhat

No data.