CVE-2006-3363: Medium severity Xoops Xoops Glossaire Module vulnerability
Published Jul 6, 2006
·Updated
PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the pa parameter.
Affected Software
1 affected component
Xoops Xoops Glossaire Module=1.7
Event History
Jul 6, 2006
CVE Published
08:05 PM
Jul 7, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3363?
CVE-2006-3363 is classified as a high-severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2006-3363?
To fix CVE-2006-3363, update the Glossaire module to the latest version or apply patches provided by the vendor.
3
What systems are affected by CVE-2006-3363?
CVE-2006-3363 affects the Xoops Glossaire module version 1.7.
4
What type of vulnerability is CVE-2006-3363?
CVE-2006-3363 is a remote file inclusion vulnerability that allows attackers to execute arbitrary PHP code.
5
Can CVE-2006-3363 be exploited remotely?
Yes, CVE-2006-3363 can be exploited remotely if the conditions are met to manipulate the 'pa' parameter.