Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2006-0636
Description:desktop.php in eyeOS 0.8.9 and earlier tests for the existence of the _SESSION variable before calling the session_start function, which allows remote attackers to execute arbitrary PHP code and possibly conduct other attacks by modifying critical assumed-immutable variables, as demonstrated using PHP code in the _SESSION[apps][eyeOptions.eyeapp][wrapup] variable.
Test IDs: 1.3.6.1.4.1.25623.1.0.80008  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2006-0636
BugTraq ID: 16537
http://www.securityfocus.com/bid/16537
Bugtraq: 20060207 eyeOS <= 0.8.9 Remote Code Execution (Google Search)
http://www.securityfocus.com/archive/1/424329/100/0/threaded
http://www.gulftech.org/?node=research&article_id=00096-02072006
http://securitytracker.com/id?1015609
http://secunia.com/advisories/18757
http://securityreason.com/securityalert/419
http://www.vupen.com/english/advisories/2006/0466
XForce ISS Database: eyeos-desktop-file-include(24569)
https://exchange.xforce.ibmcloud.com/vulnerabilities/24569




© 1998-2025 E-Soft Inc. All rights reserved.