First published: Mon Feb 13 2006(Updated: )
Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen enabled, allow remote attackers to execute arbitrary code via the bbPath[path] parameter in (1) class.forumposts.php and (2) forumpollrenderer.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Runcms Runcms | =1.1a | |
Runcms Runcms | <=1.2 | |
Runcms Runcms | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0659 is classified as a critical vulnerability due to its potential for remote code execution.
To mitigate CVE-2006-0659, disable register_globals and allow_url_fopen in your PHP configuration and upgrade to a secure version of RunCMS.
CVE-2006-0659 affects multiple versions of RunCMS up to and including 1.2, particularly 1.1 and 1.1a.
Exploiting CVE-2006-0659 allows remote attackers to execute arbitrary code on the vulnerable system.
Yes, there are known exploits for CVE-2006-0659 that leverage the vulnerabilities in the bbPath[path] parameter.