Vulnonym.com

CVE-2006-5894 - Phonier Affiants

Description

Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier when register_globals is enabled allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie as demonstrated by injecting PHP sequences into an Apache HTTP Server log file which is then included by lang.php.

Reference

http://www.rahim.webd.pl/exploit127.html http://www.securityfocus.com/bid/21009 http://secunia.com/advisories/22847 http://www.vupen.com/english/advisories/2006/4473 https://exchange.xforce.ibmcloud.com/vulnerabilities/30183 https://www.exploit-db.com/exploits/2760