First published: Tue Aug 08 2006(Updated: )
Dynamic variable evaluation vulnerability in index.php in Jetbox CMS 2.1 SR1 allows remote attackers to overwrite configuration variables via URL parameters, which are evaluated as PHP variable variables.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jetbox CMS | =2.1 | |
Jetbox CMS | =2.1_sr1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3584 is considered a high severity vulnerability due to its ability to allow remote attackers to overwrite configuration variables.
To fix CVE-2006-3584, update Jetbox CMS to a version that has patched this vulnerability, specifically versions after 2.1 SR1.
CVE-2006-3584 is a dynamic variable evaluation vulnerability that affects Jetbox CMS.
CVE-2006-3584 affects Jetbox CMS version 2.1 and 2.1 SR1.
Yes, CVE-2006-3584 can be exploited remotely by attackers through specially crafted URL parameters.