First published: Wed Aug 09 2006(Updated: )
PHP remote file inclusion vulnerability in myevent.php in myWebland myEvent 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Myevent | <=1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4040 is classified as a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2006-4040, upgrade myWebland myEvent to version 1.4 or later, which addresses this vulnerability.
CVE-2006-4040 allows attackers to execute arbitrary PHP code, leading to potential full system compromise.
CVE-2006-4040 affects myWebland myEvent versions up to and including 1.3.
While CVE-2006-4040 is an older vulnerability, systems using vulnerable versions without patches remain at risk.