First published: Thu Aug 17 2006(Updated: )
Directory traversal vulnerability in memcp.php in XMB (Extreme Message Board) 1.9.6 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the langfilenew parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by header.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xmb Software Extreme Message Board | <=1.9.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4191 is considered a critical vulnerability due to its potential for remote code execution.
To fix CVE-2006-4191, upgrade to XMB Extreme Message Board version 1.9.7 or later where this vulnerability is patched.
CVE-2006-4191 allows attackers to exploit directory traversal to include and execute arbitrary local files on the server.
CVE-2006-4191 affects XMB (Extreme Message Board) versions 1.9.6 and earlier.
Yes, CVE-2006-4191 is a publicly disclosed vulnerability that has been documented in cybersecurity databases.