CVE-2006-4190: Low severity PHP-Nuke AutoHTML module vulnerability
Published Aug 17, 2006
·Updated
Directory traversal vulnerability in autohtml.php in the AutoHTML module for PHP-Nuke allows local users to include arbitrary files via a .. (dot dot) in the name parameter for a modload operation.
Affected Software
1 affected component
PHP-Nuke AutoHTML module=2.0
Event History
Aug 17, 2006
CVE Published
01:04 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4190?
CVE-2006-4190 is classified as a medium severity vulnerability due to its ability to allow local users to include arbitrary files.
2
How do I fix CVE-2006-4190?
To fix CVE-2006-4190, update the AutoHTML module in PHP-Nuke to a version that does not allow directory traversal exploitation.
3
Who is affected by CVE-2006-4190?
CVE-2006-4190 affects users of PHP-Nuke using the AutoHTML module version 2.0.
4
What does CVE-2006-4190 exploit?
CVE-2006-4190 exploits a directory traversal vulnerability in the autohtml.php file, allowing unauthorized file inclusion.
5
Is CVE-2006-4190 a local or remote vulnerability?
CVE-2006-4190 is considered a local vulnerability, as it requires local user access to exploit.