CVE-2006-2315: Code Injection
DISPUTED PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the goinfo[server][classesroot] parameter. NOTE: the vendor has disputed this vulnerability, saying that session.inc.php is not under the web root in version 2.2, and registerglobals is not enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2315?
CVE-2006-2315 is considered a remote file inclusion vulnerability that could allow attackers to execute arbitrary PHP code.
How do I fix CVE-2006-2315?
To fix CVE-2006-2315, upgrade ISPConfig to version 2.2.3 or later.
What software is affected by CVE-2006-2315?
CVE-2006-2315 affects ISPConfig versions 2.2.2 and earlier.
Can CVE-2006-2315 be exploited remotely?
Yes, CVE-2006-2315 can be exploited by remote attackers via crafted URL parameters.
Is there a patch available for CVE-2006-2315?
There is no specific patch, but upgrading to the latest version of ISPConfig resolves the vulnerability.