PHP remote file inclusion vulnerability in include.php in Comdev CSV Importer 3.1 and possibly 4.1, as used in (1) Comdev Contact Form 3.1, (2) Comdev Customer Helpdesk 3.1, (3) Comdev Events Calendar 3.1, (4) Comdev FAQ Support 3.1, (5) Comdev Guestbook 3.1, (6) Comdev Links Directory 3.1, (7) Comdev News Publisher 3.1, (8) Comdev Newsletter 3.1, (9) Comdev Photo Gallery 3.1, (10) Comdev Vote Caster 3.1, (11) Comdev Web Blogger 3.1, and (12) Comdev eCommerce 3.1, allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. NOTE: it has been reported that 4.1 versions might also be affected.
References
Link Providers
http://secunia.com/advisories/22133 cve-icon cve-icon
http://secunia.com/advisories/22134 cve-icon cve-icon
http://secunia.com/advisories/22135 cve-icon cve-icon
http://secunia.com/advisories/22147 cve-icon cve-icon
http://secunia.com/advisories/22149 cve-icon cve-icon
http://secunia.com/advisories/22151 cve-icon cve-icon
http://secunia.com/advisories/22153 cve-icon cve-icon
http://secunia.com/advisories/22154 cve-icon cve-icon
http://secunia.com/advisories/22157 cve-icon cve-icon
http://secunia.com/advisories/22168 cve-icon cve-icon
http://secunia.com/advisories/22169 cve-icon cve-icon
http://secunia.com/advisories/22170 cve-icon cve-icon
http://securityreason.com/securityalert/1658 cve-icon cve-icon
http://www.osvdb.org/29299 cve-icon cve-icon
http://www.osvdb.org/29300 cve-icon cve-icon
http://www.osvdb.org/29301 cve-icon cve-icon
http://www.osvdb.org/29302 cve-icon cve-icon
http://www.osvdb.org/29303 cve-icon cve-icon
http://www.osvdb.org/29304 cve-icon cve-icon
http://www.osvdb.org/29305 cve-icon cve-icon
http://www.osvdb.org/29306 cve-icon cve-icon
http://www.osvdb.org/29307 cve-icon cve-icon
http://www.osvdb.org/29308 cve-icon cve-icon
http://www.osvdb.org/29309 cve-icon cve-icon
http://www.osvdb.org/29310 cve-icon cve-icon
http://www.osvdb.org/29311 cve-icon cve-icon
http://www.securityfocus.com/archive/1/447184/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/447185/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/447186/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/447187/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/447188/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/447190/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/447192/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/447193/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/447194/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/447201/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/447207/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/447209/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/447213/100/0/threaded cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3803 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3804 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3805 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3806 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3807 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3808 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3809 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3810 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3811 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3812 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3813 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3814 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3815 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/29220 cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2006-10-02T20:00:00

Updated: 2024-08-07T19:41:05.237Z

Reserved: 2006-10-02T00:00:00

Link: CVE-2006-5101

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2006-10-03T04:03:00.000

Modified: 2018-10-17T21:41:06.310

Link: CVE-2006-5101

cve-icon Redhat

No data.