CVE-2006-3736: High severity Mambo videodb vulnerability
Published Jul 19, 2006
·Updated
PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
Affected Software
3 affected components
Mambo videodb=0.3
Mambo videodb=0.1
Mambo videodb=0.2
Event History
Jul 19, 2006
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3736?
CVE-2006-3736 is considered a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2006-3736?
To fix CVE-2006-3736, upgrade the Mambo Videodb component to version 0.4 or later.
3
What are the affected versions in CVE-2006-3736?
CVE-2006-3736 affects Mambo Videodb versions 0.1, 0.2, and 0.3.
4
Who is impacted by CVE-2006-3736?
Organizations using Mambo Videodb versions 0.3 and earlier are impacted by CVE-2006-3736.
5
What type of vulnerability is CVE-2006-3736?
CVE-2006-3736 is classified as a remote file inclusion vulnerability.