CVE-2006-2845: High severity REDAXO REDAXO vulnerability
Published Jun 6, 2006
·Updated
PHP remote file inclusion vulnerability in Redaxo 3.0 up to 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the REX[INCLUDEPATH] parameter to imageresize/pages/index.inc.php.
Affected Software
2 affected components
REDAXO REDAXO=3.2
REDAXO REDAXO=3.0
Event History
Jun 6, 2006
CVE Published
08:06 PM
Jun 7, 2006
CVE Published
via MITRE·12:03 AM
Data Sourced
via MITRE·12:03 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2845?
CVE-2006-2845 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2006-2845?
To fix CVE-2006-2845, upgrade Redaxo to a version higher than 3.2 that addresses this vulnerability.
3
Which versions of Redaxo are affected by CVE-2006-2845?
CVE-2006-2845 affects Redaxo versions 3.0 to 3.2 inclusive.
4
What is the impact of CVE-2006-2845?
The impact of CVE-2006-2845 is that an attacker can execute arbitrary PHP code on the server.
5
Is CVE-2006-2845 a common vulnerability?
CVE-2006-2845 is considered common among vulnerabilities related to remote file inclusion in PHP applications.