CVE-2006-1816: Medium severity jelsoft vbulletin vulnerability
Published Apr 18, 2006
·Updated
PHP remote file inclusion vulnerability in VBulletin 3.5.1, 3.5.2, and 3.5.4 allows remote attackers to execute arbitrary code via a URL in the systempath parameter to (1) ImpExModule.php, (2) ImpExController.php, and (3) ImpExDisplay.php.
Affected Software
3 affected components
Jelsoft vBulletin=3.5.2
Jelsoft vBulletin=3.5.1
Jelsoft vBulletin=3.5.4
Event History
Apr 18, 2006
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1816?
CVE-2006-1816 is considered a critical severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2006-1816?
To fix CVE-2006-1816, upgrade to a newer version of vBulletin that has patched this vulnerability.
3
Which versions of vBulletin are affected by CVE-2006-1816?
CVE-2006-1816 affects vBulletin versions 3.5.1, 3.5.2, and 3.5.4.
4
What type of vulnerability is CVE-2006-1816?
CVE-2006-1816 is categorized as a remote file inclusion vulnerability.
5
Can CVE-2006-1816 lead to data compromise?
Yes, CVE-2006-1816 can allow attackers to execute arbitrary code, potentially leading to data compromise.