CVE-2006-5020

N/A Unknown
Published: September 27, 2006 Modified: April 23, 2026
View on NVD

Description

Multiple PHP remote file inclusion vulnerabilities in SolidState 0.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the base_path parameter in manager/pages/ scripts including (1) AccountsPage.class.php, (2) AddInvoicePage.class.php, (3) AddIPAddressPage.class.php, (4) AddPaymentPage.class.php, (5) AddTaxRulePage.class.php, (6) AssignDomainPage.class.php, (7) AssignHostingPage.class.php, (8) AssignProductPage.class.php, (9) BillingPage.class.php, (10) BillingPaymentPage.class.php, (11) BrowseAccountsPage.class.php, (12) BrowseInvoicesPage.class.php, (13) ConfigureEditUserPage.class.php, (14) ConfigureNewUserPage.class.php, (15) ConfigureNewUserReceiptPage.class.php, (16) ConfigureUsersPage.class.php, (17) DeleteAccountPage.class.php, (18) DeleteDomainServicePage.class.php, (19) DeleteHostingServicePage.class.php, (20) DeleteInvoicePage.class.php, (21) DeleteProductPage.class.php, (22) DeleteServerPage.class.php, (23) DomainServicesPage.class.php, (24) DomainsPage.class.php, (25) EditAccountPage.class.php, (26) EditDomainPage.class.php, (27) EditDomainServicePage.class.php, (28) EditHostingServicePage.class.php, (29) EditPaymentPage.class.php, (30) EditProductPage.class.php, (31) EditServerPage.class.php, (32) EmailInvoicePage.class.php, (33) ExecuteOrderPage.class.php, (34) ExpiredDomainsPage.class.php, (35) FulfilledOrdersPage.class.php, (36) GenerateInvoicesPage.class.php, (37) HomePage.class.php, (38) InactiveAccountsPage.class.php, (39) IPManagerPage.class.php, (40) LoginPage.class.php, (41) LogPage.class.php, (42) ModulesPage.class.php, (43) NewAccountPage.class.php, (44) NewDomainServicePage.class.php, (45) NewProductPage.class.php, (46) OutstandingInvoicesPage.class.php, (47) PendingAccountsPage.class.php, (48) PendingOrdersPage.class.php, (49) PrintInvoicePage.class.php, (50) ProductsPage.class.php, (51) RegisterDomainPage.class.php, (52) RegisteredDomainsPage.class.php, (53) ServersPage.class.php, (54) ServicesHostingServicesPage.class.php, (55) ServicesNewHostingPage.class.php, (56) ServicesPage.class.php, (57) ServicesWebHostingPage.class.php, (58) SettingsPage.class.php, (59) TaxesPage.class.php, (60) TransferDomainPage.class.php, (61) ViewAccountPage.class.php, (62) ViewDomainServicePage.class.php, (63) ViewHostingServicePage.class.php, (64) ViewInvoicePage.class.php, (65) ViewLogMessagePage.class.php, (66) ViewOrderPage.class.php, (67) ViewProductPage.class.php, (68) ViewServerPage.class.php, (69) WelcomeEmailPage.class.php; and (70) modules/RegistrarModule.class.php, (71) modules/SolidStateModule.class.php, (72) modules/authorizeaim/authorizeaim.class.php, and (73) modules/authorizeaim/pages/AAIMConfigPage.class.php.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://www.osvdb.org/31097
Source: cve@mitre.org
http://www.osvdb.org/31098
Source: cve@mitre.org
http://www.osvdb.org/31099
Source: cve@mitre.org
http://www.osvdb.org/31100
Source: cve@mitre.org
http://www.osvdb.org/31104
Source: cve@mitre.org
http://www.osvdb.org/31105
Source: cve@mitre.org
http://www.osvdb.org/31106
Source: cve@mitre.org
http://www.osvdb.org/31107
Source: cve@mitre.org
http://www.osvdb.org/31108
Source: cve@mitre.org
http://www.osvdb.org/31109
Source: cve@mitre.org
http://www.osvdb.org/31110
Source: cve@mitre.org
http://www.osvdb.org/31111
Source: cve@mitre.org
http://www.osvdb.org/31112
Source: cve@mitre.org
http://www.osvdb.org/31113
Source: cve@mitre.org
http://www.osvdb.org/31114
Source: cve@mitre.org
http://www.osvdb.org/31115
Source: cve@mitre.org
http://www.osvdb.org/31116
Source: cve@mitre.org
http://www.osvdb.org/31117
Source: cve@mitre.org
http://www.osvdb.org/31118
Source: cve@mitre.org
http://www.osvdb.org/31119
Source: cve@mitre.org
http://www.osvdb.org/31120
Source: cve@mitre.org
http://www.osvdb.org/31121
Source: cve@mitre.org
http://www.osvdb.org/31122
Source: cve@mitre.org
http://www.osvdb.org/31123
Source: cve@mitre.org
http://www.osvdb.org/31124
Source: cve@mitre.org
http://www.osvdb.org/31125
Source: cve@mitre.org
http://www.osvdb.org/31126
Source: cve@mitre.org
http://www.osvdb.org/31127
Source: cve@mitre.org
http://www.osvdb.org/31128
Source: cve@mitre.org
http://www.osvdb.org/31129
Source: cve@mitre.org
http://www.osvdb.org/31130
Source: cve@mitre.org
http://www.osvdb.org/31131
Source: cve@mitre.org
http://www.osvdb.org/31132
Source: cve@mitre.org
http://www.osvdb.org/31133
Source: cve@mitre.org
http://www.osvdb.org/31134
Source: cve@mitre.org
http://www.osvdb.org/31135
Source: cve@mitre.org
http://www.osvdb.org/31136
Source: cve@mitre.org
http://www.osvdb.org/31137
Source: cve@mitre.org
http://www.osvdb.org/31138
Source: cve@mitre.org
http://www.osvdb.org/31139
Source: cve@mitre.org
http://www.osvdb.org/31141
Source: cve@mitre.org
http://www.osvdb.org/31142
Source: cve@mitre.org
http://www.osvdb.org/31143
Source: cve@mitre.org
http://www.osvdb.org/31144
Source: cve@mitre.org
http://www.osvdb.org/31145
Source: cve@mitre.org
http://www.osvdb.org/31146
Source: cve@mitre.org
http://www.osvdb.org/31147
Source: cve@mitre.org
http://www.osvdb.org/31190
Source: cve@mitre.org
http://www.osvdb.org/31191
Source: cve@mitre.org
http://www.osvdb.org/31192
Source: cve@mitre.org
http://www.osvdb.org/31193
Source: cve@mitre.org
http://www.osvdb.org/31194
Source: cve@mitre.org
http://www.osvdb.org/31197
Source: cve@mitre.org
http://www.osvdb.org/31198
Source: cve@mitre.org
http://www.osvdb.org/31199
Source: cve@mitre.org
http://www.osvdb.org/31200
Source: cve@mitre.org
http://www.osvdb.org/31201
Source: cve@mitre.org
http://www.osvdb.org/31202
Source: cve@mitre.org
http://www.osvdb.org/31203
Source: cve@mitre.org
http://attrition.org/pipermail/vim/2007-January/001210.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31097
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31098
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31099
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31100
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31104
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31105
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31106
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31107
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31108
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31109
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31110
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31111
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31112
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31113
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31114
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31115
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31116
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31117
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31118
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31119
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31120
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31121
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31122
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31123
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31124
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31125
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31126
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31127
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31128
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31129
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31130
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31131
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31132
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31133
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31134
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31135
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31136
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31137
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31138
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31139
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31141
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31142
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31143
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31144
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31145
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31146
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31147
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31190
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31191
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31192
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31193
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31194
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31197
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31198
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31199
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31200
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31201
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31202
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/31203
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/21934
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/29095
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.exploit-db.com/exploits/2413
Source: af854a3a-2127-422b-91ae-364da2661108

128 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
Exploitation Status
Not in CISA KEV

Affected Vendors

solidstate