CVE-2006-1688

N/A Unknown
Published: April 11, 2006 Modified: April 16, 2026
View on NVD

Description

Multiple PHP remote file inclusion vulnerabilities in SQuery 4.5 and earlier, as used in products such as Autonomous LAN party (ALP), allow remote attackers to execute arbitrary PHP code via a URL in the libpath parameter to scripts in the lib directory including (1) ase.php, (2) devi.php, (3) doom3.php, (4) et.php, (5) flashpoint.php, (6) gameSpy.php, (7) gameSpy2.php, (8) gore.php, (9) gsvari.php, (10) halo.php, (11) hlife.php, (12) hlife2.php, (13) igi2.php, (14) main.lib.php, (15) netpanzer.php, (16) old_hlife.php, (17) pkill.php, (18) q2a.php, (19) q3a.php, (20) qworld.php, (21) rene.php, (22) rvbshld.php, (23) savage.php, (24) simracer.php, (25) sof1.php, (26) sof2.php, (27) unreal.php, (28) ut2004.php, and (29) vietcong.php. NOTE: the lib/armygame.php vector is already covered by CVE-2006-1610. The provenance of most of these additional vectors is unknown, although likely from post-disclosure analysis. NOTE: this only occurs when register_globals is disabled.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://liz0zim.no-ip.org/alp.txt
Source: cve@mitre.org
Exploit
http://secunia.com/advisories/19482
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/19588
Source: cve@mitre.org
Vendor Advisory
http://securitytracker.com/id?1015884
Source: cve@mitre.org
Exploit
http://www.blogcu.com/Liz0ziM/431845/
Source: cve@mitre.org
Exploit URL Repurposed
http://www.osvdb.org/24401
Source: cve@mitre.org
http://www.osvdb.org/24402
Source: cve@mitre.org
http://www.osvdb.org/24403
Source: cve@mitre.org
http://www.osvdb.org/24404
Source: cve@mitre.org
http://www.osvdb.org/24405
Source: cve@mitre.org
http://www.osvdb.org/24406
Source: cve@mitre.org
http://www.osvdb.org/24407
Source: cve@mitre.org
Exploit
http://www.osvdb.org/24408
Source: cve@mitre.org
http://www.osvdb.org/24409
Source: cve@mitre.org
http://www.osvdb.org/24410
Source: cve@mitre.org
http://www.osvdb.org/24411
Source: cve@mitre.org
http://www.osvdb.org/24412
Source: cve@mitre.org
http://www.osvdb.org/24413
Source: cve@mitre.org
http://www.osvdb.org/24414
Source: cve@mitre.org
http://www.osvdb.org/24415
Source: cve@mitre.org
http://www.osvdb.org/24416
Source: cve@mitre.org
http://www.osvdb.org/24417
Source: cve@mitre.org
http://www.osvdb.org/24418
Source: cve@mitre.org
http://www.osvdb.org/24419
Source: cve@mitre.org
http://www.osvdb.org/24420
Source: cve@mitre.org
http://www.osvdb.org/24421
Source: cve@mitre.org
http://www.osvdb.org/24422
Source: cve@mitre.org
http://www.osvdb.org/24423
Source: cve@mitre.org
http://www.osvdb.org/24424
Source: cve@mitre.org
http://www.osvdb.org/24425
Source: cve@mitre.org
http://www.osvdb.org/24426
Source: cve@mitre.org
http://www.osvdb.org/24427
Source: cve@mitre.org
http://www.osvdb.org/24428
Source: cve@mitre.org
http://www.osvdb.org/24429
Source: cve@mitre.org
http://www.securityfocus.com/bid/17434
Source: cve@mitre.org
Exploit
http://www.vupen.com/english/advisories/2006/1284
Source: cve@mitre.org
Vendor Advisory
http://liz0zim.no-ip.org/alp.txt
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://secunia.com/advisories/19482
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/19588
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://securityreason.com/securityalert/679
Source: af854a3a-2127-422b-91ae-364da2661108
http://securitytracker.com/id?1015884
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.blogcu.com/Liz0ziM/431845/
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit URL Repurposed
http://www.osvdb.org/24401
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24402
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24403
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24404
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24405
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24406
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24407
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.osvdb.org/24408
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24409
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24410
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24411
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24412
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24413
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24414
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24415
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24416
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24417
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24418
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24419
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24420
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24421
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24422
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24423
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24424
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24425
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24426
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24427
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24428
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24429
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/430289/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/439874/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/441015/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/17434
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.vupen.com/english/advisories/2006/1284
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

80 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
3.5%
88th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

squery