CVE-2006-1957: Input Validation
The comrss option (rss.php) in (1) Mambo and (2) Joomla! allows remote attackers to cause a denial of service (disk consumption and possibly web-server outage) via multiple requests with different values of the feed parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1957?
CVE-2006-1957 is considered a medium severity vulnerability due to its potential to cause denial of service through disk consumption.
How can I fix CVE-2006-1957?
To fix CVE-2006-1957, it is recommended to limit the request rate or filter incoming requests to the com_rss option.
Which software is affected by CVE-2006-1957?
CVE-2006-1957 affects both Mambo and Joomla! software platforms.
What type of attack is possible with CVE-2006-1957?
CVE-2006-1957 allows attackers to launch a denial of service attack targeting disk space and potentially causing web server outages.
What component of Joomla! and Mambo is vulnerable in CVE-2006-1957?
The com_rss component in the rss.php file is the vulnerable part of Joomla! and Mambo in CVE-2006-1957.