CVE-2006-1382: High severity Jelsoft Impex vulnerability
Published Mar 24, 2006
·Updated
PHP remote file inclusion vulnerability in impex/ImpExData.php in vBulletin ImpEx module 1.74, when registerglobals is disabled, allows remote attackers to include arbitrary files via the systempath parameter.
Affected Software
1 affected component
Jelsoft Impex<=1.74
Event History
Mar 24, 2006
CVE Published
11:02 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1382?
CVE-2006-1382 is considered a high severity vulnerability due to the potential for remote file inclusion.
2
How do I fix CVE-2006-1382?
To fix CVE-2006-1382, upgrade to a version of the vBulletin ImpEx module later than 1.74 that has mitigated this vulnerability.
3
What impacts does CVE-2006-1382 have on affected systems?
CVE-2006-1382 allows attackers to include arbitrary files, potentially leading to a complete compromise of the system.
4
What software is affected by CVE-2006-1382?
CVE-2006-1382 affects version 1.74 of the vBulletin ImpEx module.
5
Can CVE-2006-1382 be exploited without register_globals enabled?
Yes, CVE-2006-1382 can still be exploited even when register_globals is disabled, making it a critical vulnerability.