CVE-2006-3749: Code Injection
PHP remote file inclusion vulnerability in sitemap.xml.php in Sitemap component (comsitemap) 2.0.0 for Mambo 4.5.1 CMS, when registerglobals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3749?
CVE-2006-3749 is considered a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2006-3749?
To fix CVE-2006-3749, disable register_globals in your PHP configuration and upgrade the Mambo Sitemap component to a secured version.
What systems are affected by CVE-2006-3749?
CVE-2006-3749 affects Mambo CMS version 4.5.1 with the Sitemap component version 2.0.0.
Can CVE-2006-3749 be exploited without authentication?
Yes, CVE-2006-3749 can be exploited remotely without any authentication.
Is there a workaround for CVE-2006-3749 besides upgrading?
A temporary workaround for CVE-2006-3749 is to disable or restrict access to the affected file until a patch is applied.