CVE-2006-0147: High severity Postnuke Software Foundation Postnuke vulnerability
Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to execute arbitrary PHP functions via the do parameter, which is saved in a variable that is then executed as a function, as demonstrated using phpinfo.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0147?
CVE-2006-0147 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2006-0147?
To fix CVE-2006-0147, upgrade ADOdb to version 4.70 or later.
Which software is affected by CVE-2006-0147?
CVE-2006-0147 affects multiple products including Mantis, PostNuke, Moodle, Cacti, and various versions of ADOdb.
What types of attacks are possible due to CVE-2006-0147?
CVE-2006-0147 allows remote attackers to execute arbitrary code on affected systems.
Is CVE-2006-0147 exploitable without authentication?
Yes, CVE-2006-0147 can be exploited by an attacker remotely without needing authentication.