CVE-2006-3980: Code Injection
Published Aug 5, 2006
·Updated
PHP remote file inclusion vulnerability in administrator/components/commgm/help.mgm.php in Mambo Gallery Manager (MGM) 0.95r2 and earlier for Mambo 4.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
Affected Software
1 affected component
Mambo Mambo Gallery Manager<=0.95r2
Event History
Aug 5, 2006
CVE Published
12:04 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3980?
The severity of CVE-2006-3980 is considered high due to its potential for remote code execution.
2
How do I fix CVE-2006-3980?
To fix CVE-2006-3980, upgrade to a version of Mambo Gallery Manager later than 0.95r2 that includes security patches.
3
What systems are affected by CVE-2006-3980?
CVE-2006-3980 affects Mambo Gallery Manager version 0.95r2 and earlier for Mambo 4.5.
4
What type of vulnerability is CVE-2006-3980?
CVE-2006-3980 is a remote file inclusion vulnerability that allows execution of arbitrary PHP code.
5
Can CVE-2006-3980 be exploited remotely?
Yes, CVE-2006-3980 can be exploited remotely by attackers through a crafted URL.