First published: Tue Apr 04 2006(Updated: )
PHP remote file inclusion vulnerability in includes/functions_common.php in the VWar Account module (vWar_Account) in PHPNuke Clan 3.0.1 allows remote attackers to include arbitrary files via a URL in the vwar_root2 parameter. NOTE: it is possible that this issue stems from a problem in VWar itself, but this is not clear.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP-Nuke | =3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1602 is classified as a critical vulnerability due to the potential for remote code execution via file inclusion.
To fix CVE-2006-1602, upgrade PHPNuke Clan to a patched version that mitigates the remote file inclusion issue.
CVE-2006-1602 affects PHPNuke Clan version 3.0.1.
CVE-2006-1602 can be exploited by remote attackers to include arbitrary files on the server.
CVE-2006-1602 is a historical vulnerability and represents concerns that can still apply to applications using outdated code or configurations.