CVE-2006-3846: Code Injection
Published Jul 25, 2006
·Updated
PHP remote file inclusion vulnerability in extadminmenus.class.php in the MultiBanners 1.0.1 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
Affected Software
1 affected component
Mambo Mambo Multibanners=1.0.1
Event History
Jul 25, 2006
CVE Published
11:04 PM
Jul 26, 2006
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3846?
CVE-2006-3846 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2006-3846?
To fix CVE-2006-3846, update the MultiBanners component to a version that does not contain this vulnerability.
3
What systems are affected by CVE-2006-3846?
CVE-2006-3846 specifically affects MultiBanners 1.0.1 for Mambo.
4
What type of vulnerability is CVE-2006-3846?
CVE-2006-3846 is classified as a remote file inclusion vulnerability.
5
Can CVE-2006-3846 be exploited without authentication?
Yes, CVE-2006-3846 can be exploited by remote attackers without requiring authentication.