CVE-2006-4269: High severity Mambo x-shop component vulnerability
DISPUTED PHP remote file inclusion vulnerability in admin.x-shop.php in the x-shop component (comx-shop) 1.7 and earlier for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter. NOTE: this issue has been disputed by third party researchers, stating that there is no mosConfigabsolutepath parameter and no admin.x-shop.php file in the reported package.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4269?
The severity of CVE-2006-4269 is considered high due to the potential for remote code execution.
How do I fix CVE-2006-4269?
To fix CVE-2006-4269, upgrade the x-shop component to a version later than 1.7.
Which software versions are affected by CVE-2006-4269?
CVE-2006-4269 affects versions of the x-shop component 1.7 and earlier for both Mambo and Joomla!.
What type of vulnerability is CVE-2006-4269?
CVE-2006-4269 is a remote file inclusion vulnerability that allows remote attackers to execute arbitrary PHP code.
Is CVE-2006-4269 still a threat today?
While CVE-2006-4269 has been known for years, its threat level depends on whether vulnerable versions are still in use.