PHP remote file inclusion vulnerability in get_header.php in VWar 1.5.0 R12 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter. NOTE: this is a different vulnerability than CVE-2006-1503.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2006-04-06 10:04
Updated : 2025-04-03 01:03
NVD link : CVE-2006-1636
Mitre link : CVE-2006-1636
CVE.ORG link : CVE-2006-1636
JSON object : View
Products Affected
vwar
- virtual_war
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')