First published: Thu Aug 10 2006(Updated: )
Multiple PHP remote file inclusion vulnerabilities in Dmitry Sheiko SAPID Gallery 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter to (a) usr/extensions/get_calendar.inc.php or the (2) GLOBALS[root_path] parameter to (b) usr/extensions/get_tree.inc.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAPID | <=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4065 is considered a high severity vulnerability due to the potential for remote code execution.
To fix CVE-2006-4065, upgrade to a version of SAPID Gallery that is newer than 1.0.
Attackers can exploit CVE-2006-4065 by sending malicious input via the root_path parameter to specific PHP files.
CVE-2006-4065 affects SAPID Gallery version 1.0 and earlier.
Yes, CVE-2006-4065 can lead to server compromise as it allows remote attackers to execute arbitrary PHP code.