CVE-2006-2578: Medium severity eSyndiCat eSyndicat Directory vulnerability
Published May 24, 2006
·Updated
admin/cron.php in eSyndicat Directory 1.2, when registerglobals is enabled and magicquotesgpc is disabled, allows remote attackers to include arbitrary files and possibly execute arbitrary PHP code via a null-terminated value in the pathtoconfig parameter.
Affected Software
1 affected component
eSyndiCat eSyndicat Directory=1.2
Event History
May 24, 2006
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2578?
CVE-2006-2578 is considered a medium severity vulnerability due to remote code execution potential.
2
How do I fix CVE-2006-2578?
To fix CVE-2006-2578, disable register_globals and enable magic_quotes_gpc in your PHP configuration.
3
Who is affected by CVE-2006-2578?
CVE-2006-2578 affects users of eSyndicat Directory version 1.2 with specific PHP configurations.
4
What type of attack is facilitated by CVE-2006-2578?
CVE-2006-2578 allows remote attackers to execute arbitrary PHP code through file inclusion.
5
What system configurations increase the risk of CVE-2006-2578?
Enabling register_globals and disabling magic_quotes_gpc increases the risk of CVE-2006-2578.