CVE-2006-4264: Critical severity Mambo Mtg Myhomepage Component vulnerability
DISPUTED Multiple PHP remote file inclusion vulnerabilities in the lmtgmyhomepage Component (comlmtgmyhomepage) for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter in (1) install.lmtghomepage.php and (2) mtghomepage.php. NOTE: this issue has been disputed by a third party, who states that the $mosConfigabsolutepath variable is only used within a function definition. CVE source code analysis on 20060824 is not conclusive but tends to concur with the dispute. In addition, it appears that the component name is actually "lmtgmyhomepage".
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4264?
CVE-2006-4264 is considered a high severity vulnerability due to its remote file inclusion potential.
How do I fix CVE-2006-4264?
To fix CVE-2006-4264, you should update the Mambo Mtg Myhomepage Component to the latest version.
What are the consequences of exploiting CVE-2006-4264?
Exploiting CVE-2006-4264 can allow an attacker to execute arbitrary PHP code on the server.
Which software is affected by CVE-2006-4264?
CVE-2006-4264 affects the Mambo Mtg Myhomepage Component.
How does CVE-2006-4264 work?
CVE-2006-4264 exploits improper validation of the mosConfig_absolute_path parameter in specific PHP files.