CVE-2006-4163: High severity myWebland miniBloggie vulnerability
DISPUTED PHP remote file inclusion vulnerability in clsfasttemplate.php in myWebland miniBloggie 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fname parameter. NOTE: another researcher was unable to find a way to execute code after including it via a URL. CVE analysis as of 20060816 was inconclusive.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4163?
CVE-2006-4163 is classified as a remote file inclusion vulnerability that could allow attackers to execute arbitrary PHP code.
How do I fix CVE-2006-4163?
To fix CVE-2006-4163, update myWebland miniBloggie to a version later than 1.0 or implement input validation to restrict the fname parameter.
Which versions of myWebland miniBloggie are affected by CVE-2006-4163?
CVE-2006-4163 affects myWebland miniBloggie version 1.0 and earlier.
What is the impact of exploiting CVE-2006-4163?
Exploiting CVE-2006-4163 allows attackers to execute arbitrary PHP code on the server running the vulnerable version of myWebland miniBloggie.
Is there a workaround for CVE-2006-4163?
A potential workaround for CVE-2006-4163 is to disable the fname parameter or employ security measures that restrict remote file inclusions.