CVE-2006-3843: High severity Mambo Mambo Calendar vulnerability
Published Jul 25, 2006
·Updated
PHP remote file inclusion vulnerability in comcalendar.php in Calendar Mambo Module 1.5.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the absolutepath parameter.
Affected Software
1 affected component
Mambo Mambo Calendar=1.5.7
Event History
Jul 25, 2006
CVE Published
11:04 PM
Jul 26, 2006
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3843?
CVE-2006-3843 has a critical severity rating due to the potential for remote code execution.
2
How do I fix CVE-2006-3843?
To fix CVE-2006-3843, upgrade to Mambo Calendar version 1.5.8 or later.
3
What systems are affected by CVE-2006-3843?
CVE-2006-3843 affects Mambo Calendar versions 1.5.7 and earlier.
4
What are the potential impacts of CVE-2006-3843?
The potential impacts of CVE-2006-3843 include unauthorized execution of PHP code, leading to complete system compromise.
5
Can CVE-2006-3843 be exploited remotely?
Yes, CVE-2006-3843 can be exploited remotely by attackers through crafted URLs.