CVE-2006-3584: High severity Jetbox Jetbox CMS vulnerability
Published Aug 8, 2006
·Updated
Dynamic variable evaluation vulnerability in index.php in Jetbox CMS 2.1 SR1 allows remote attackers to overwrite configuration variables via URL parameters, which are evaluated as PHP variable variables.
Affected Software
2 affected components
Jetbox Jetbox CMS=2.1
Jetbox Jetbox CMS=2.1_sr1
Event History
Aug 8, 2006
CVE Published
11:04 PM
Aug 9, 2006
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3584?
CVE-2006-3584 is considered a high severity vulnerability due to its ability to allow remote attackers to overwrite configuration variables.
2
How do I fix CVE-2006-3584?
To fix CVE-2006-3584, update Jetbox CMS to a version that has patched this vulnerability, specifically versions after 2.1 SR1.
3
What type of vulnerability is CVE-2006-3584?
CVE-2006-3584 is a dynamic variable evaluation vulnerability that affects Jetbox CMS.
4
What versions of Jetbox CMS are affected by CVE-2006-3584?
CVE-2006-3584 affects Jetbox CMS version 2.1 and 2.1 SR1.
5
Can CVE-2006-3584 be exploited remotely?
Yes, CVE-2006-3584 can be exploited remotely by attackers through specially crafted URL parameters.