CVE-2006-3949: Code Injection
Published Aug 1, 2006
·Updated
PHP remote file inclusion vulnerability in artlinks.dispnew.php in the Artlinks component (comartlinks) for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
Affected Software
1 affected component
Mambo Artlinks component
Event History
Aug 1, 2006
CVE Published
09:04 PM
Aug 2, 2006
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3949?
CVE-2006-3949 has a high severity level due to the risk of remote code execution.
2
How do I fix CVE-2006-3949?
To fix CVE-2006-3949, update the Artlinks component to a version that has addressed this vulnerability.
3
Who is affected by CVE-2006-3949?
CVE-2006-3949 affects users of the Mambo CMS with the Artlinks component installed.
4
What type of vulnerability is CVE-2006-3949?
CVE-2006-3949 is a remote file inclusion vulnerability.
5
Can CVE-2006-3949 be exploited remotely?
Yes, CVE-2006-3949 can be exploited remotely by attackers.