CVE-2006-5831: High severity AIOCP AIOCP vulnerability
PHP remote file inclusion vulnerability in admin/code/index.php in All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the loadpage parameter.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker needs network access to the affected AIOCP installation and the ability to send a request to admin/code/index.php with a URL supplied in the load_page parameter. No authentication is required according to the provided attack vector.
Which deployments are affected?
AIOCP version 1.3.007 and earlier are affected. The vulnerability is in the administrative script admin/code/index.php, but the provided data does not state whether additional access controls or server configuration could limit exposure.
What is the impact of successful exploitation?
A remote attacker can execute arbitrary PHP code. This can compromise confidentiality, integrity, and availability of the affected system.