First published: Fri Apr 21 2006(Updated: )
The com_rss option (rss.php) in (1) Mambo and (2) Joomla! allows remote attackers to obtain sensitive information via an invalid feed parameter, which reveals the path in an error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mambo (MamboCMS) | =4.5.3h-h | |
Joomla | =1.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1956 is classified as a medium severity vulnerability.
To mitigate CVE-2006-1956, update to the latest versions of Joomla! or Mambo that contain security patches.
CVE-2006-1956 allows remote attackers to exploit the vulnerability to disclose sensitive information through error messages.
CVE-2006-1956 affects Mambo version 4.5.3h-h and Joomla! version 1.0.7.
Yes, CVE-2006-1956 can be exploited by remotely manipulating the feed parameter in the RSS module.