CVE-2006-0871: Path Traversal
Published Feb 24, 2006
·Updated
Directory traversal vulnerability in the setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to read and include arbitrary files via the moschangetemplate parameter. NOTE: CVE-2006-1794 has been assigned to the SQL injection vector.
Affected Software
2 affected components
Mambo Mambo=4.5.3h-h
Mambo Mambo=4.5.3h
Remediation
Patch Available
Event History
Feb 24, 2006
CVE Published
11:02 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0871?
CVE-2006-0871 has a moderate severity rating, as it allows remote attackers to access arbitrary files.
2
How do I fix CVE-2006-0871?
To fix CVE-2006-0871, upgrade Mambo to version 4.5.3h or later, which contains security patches.
3
What software is affected by CVE-2006-0871?
CVE-2006-0871 affects Mambo versions 4.5.3, 4.5.3h, and possibly earlier releases.
4
What type of vulnerability is CVE-2006-0871?
CVE-2006-0871 is classified as a directory traversal vulnerability.
5
Who can exploit CVE-2006-0871?
CVE-2006-0871 can be exploited by remote attackers who can manipulate the mos_change_template parameter.