CVE-2006-3969: High severity Joomla colophon vulnerability
Published Aug 1, 2006
·Updated
PHP remote file inclusion vulnerability in administrator/components/comcolophon/admin.colophon.php in Colophon 1.2 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
Affected Software
1 affected component
Joomla colophon<=1.2
Event History
Aug 1, 2006
CVE Published
10:04 PM
Aug 2, 2006
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3969?
CVE-2006-3969 is classified as a high-severity remote file inclusion vulnerability.
2
How do I fix CVE-2006-3969?
To fix CVE-2006-3969, update Colophon to a version newer than 1.2 that does not include this vulnerability.
3
What software is affected by CVE-2006-3969?
CVE-2006-3969 affects all versions of Colophon 1.2 and earlier for Joomla!.
4
What type of vulnerability is CVE-2006-3969?
CVE-2006-3969 is a remote file inclusion vulnerability that allows arbitrary PHP code execution.
5
Who can exploit CVE-2006-3969?
CVE-2006-3969 can be exploited by remote attackers who can manipulate the mosConfig_absolute_path parameter.