CVE-2006-2844: High severity REDAXO REDAXO vulnerability
Published Jun 6, 2006
·Updated
Multiple PHP remote file inclusion vulnerabilities in Redaxo 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the REX[INCLUDEPATH] parameter to (1) simpleuser/pages/index.inc.php and (2) stats/pages/index.inc.php.
Affected Software
1 affected component
REDAXO REDAXO=3.0
Event History
Jun 6, 2006
CVE Published
08:06 PM
Jun 7, 2006
CVE Published
via MITRE·12:03 AM
Data Sourced
via MITRE·12:03 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2844?
CVE-2006-2844 is considered a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2006-2844?
To fix CVE-2006-2844, upgrade Redaxo to a patched version that addresses the remote file inclusion vulnerability.
3
What software is affected by CVE-2006-2844?
CVE-2006-2844 affects Redaxo version 3.0.
4
Can CVE-2006-2844 be exploited remotely?
Yes, CVE-2006-2844 can be exploited remotely by attackers to execute arbitrary PHP code.
5
What parameters are involved in CVE-2006-2844?
CVE-2006-2844 involves the REX[INCLUDE_PATH] parameter in specific Redaxo PHP files.