First published: Mon Aug 21 2006(Updated: )
PHP remote file inclusion vulnerability in index.php in Fusion News 3.7 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP-Fusion | =3.3 | |
PHP-Fusion | =3.6.1 | |
PHP-Fusion | =1.0 | |
PHP-Fusion | =3.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4240 has a medium severity rating as it allows remote code execution.
To fix CVE-2006-4240, upgrade to a patched version of Fusion News that does not have this vulnerability.
CVE-2006-4240 affects Fusion News version 1.0, 3.3, 3.6.1, and 3.7.
Yes, CVE-2006-4240 can be exploited remotely via the fpath parameter in index.php.
CVE-2006-4240 is a remote file inclusion vulnerability.