First published: Fri Jun 09 2006(Updated: )
PHP remote file inclusion vulnerability in contrib/forms/evaluation/C_FormEvaluation.class.php in OpenEMR 2.8.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[fileroot] parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR | <=2.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2929 has a medium severity level due to its potential for remote code execution.
To fix CVE-2006-2929, disable register_globals in PHP configuration and upgrade to OpenEMR version 2.8.2 or later.
CVE-2006-2929 affects OpenEMR versions 2.8.1 and earlier.
CVE-2006-2929 allows remote attackers to execute arbitrary PHP code through remote file inclusion.
CVE-2006-2929 was reported in June 2006.