CVE-2006-4077: High severity Comet Comet Webfile Manager vulnerability
PHP remote file inclusion vulnerability in CheckUpload.php in Vincenzo Valvano Comet WebFileManager (CWFM) 0.9.1, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the Language parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4077?
The severity of CVE-2006-4077 is rated as high, with a score of 7.5 on the CVSS scale.
How does CVE-2006-4077 affect the Comet WebFileManager?
CVE-2006-4077 allows remote attackers to execute arbitrary PHP code by exploiting a remote file inclusion vulnerability in the Language parameter of CheckUpload.php.
What versions of Comet WebFileManager are impacted by CVE-2006-4077?
CVE-2006-4077 affects Comet WebFileManager version 0.9.1 and possibly earlier versions.
How can I fix CVE-2006-4077?
To fix CVE-2006-4077, ensure that your Comet WebFileManager is updated to a version that has patched this vulnerability.
What should I do if I cannot patch CVE-2006-4077 immediately?
If immediate patching is not possible, you should restrict access to the affected components and monitor for any suspicious activity.