CVE-2006-1746: Path Traversal
Published Apr 12, 2006
·Updated
Directory traversal vulnerability in PHPList 2.10.2 and earlier allows remote attackers to include arbitrary local files via the (1) GLOBALS[databasemodule] or (2) GLOBALS[languagemodule] parameters, which overwrite the underlying $GLOBALS variable.
Affected Software
13 affected components
Tincan Phplist=2.8.2
Tincan Phplist=2.6.3
Tincan Phplist=2.6.5
Tincan Phplist=2.6
Tincan Phplist=2.8.12
Tincan Phplist=2.6.2
Tincan Phplist=2.6.4
Tincan Phplist=2.8.7
Tincan Phplist=2.10.1
Tincan Phplist=2.6.1
Tincan Phplist<=2.10.2
Tincan Phplist=2.7.1
Tincan Phplist=2.7.2
Remediation
Patch Available
Event History
Apr 12, 2006
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1746?
CVE-2006-1746 is considered a high severity vulnerability due to its potential for remote file inclusion and execution.
2
How do I fix CVE-2006-1746?
To fix CVE-2006-1746, upgrade PHPList to version 2.10.3 or later, which addresses this vulnerability.
3
What versions of PHPList are affected by CVE-2006-1746?
CVE-2006-1746 affects PHPList versions 2.10.2 and earlier.
4
What types of attacks can CVE-2006-1746 enable?
CVE-2006-1746 can enable remote attackers to execute arbitrary code by including local files.
5
Are there any known exploits for CVE-2006-1746?
Yes, there are known exploits that demonstrate how to leverage CVE-2006-1746 for directory traversal attacks.