First published: Thu Aug 10 2006(Updated: )
PHP remote file inclusion vulnerability in usr/extensions/get_tree.inc.php in Dmitry Sheiko SAPID Shop 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[root_path] parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAPID | <=1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4062 is considered a high severity vulnerability due to its remote file inclusion nature that can lead to arbitrary code execution.
To fix CVE-2006-4062, upgrade to a version of SAPID Shop that is later than 1.2 to eliminate the vulnerability.
CVE-2006-4062 is a remote file inclusion vulnerability that allows attackers to run arbitrary PHP code.
CVE-2006-4062 affects SAPID Shop version 1.2 and earlier.
The vendor associated with CVE-2006-4062 is Dmitry Sheiko, the developer of SAPID Shop.