CVE-2006-4275: High severity Mambo CatalogShop component vulnerability
PHP remote file inclusion vulnerability in catalogshop.php in the CatalogShop component for Mambo (comcatalogshop) allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4275?
CVE-2006-4275 is considered to have a medium severity level due to the potential for remote code execution.
How do I fix CVE-2006-4275?
To fix CVE-2006-4275, upgrade the CatalogShop component for Mambo to a version that addresses this vulnerability.
What type of attacks can be performed using CVE-2006-4275?
CVE-2006-4275 allows remote attackers to execute arbitrary PHP code, potentially compromising the affected system.
Is CVE-2006-4275 specific to any version of Mambo?
Yes, CVE-2006-4275 specifically affects version 1.0_beta_2 of the CatalogShop component for Mambo.
What are the conditions needed for CVE-2006-4275 to be exploited?
CVE-2006-4275 can be exploited when an attacker provides a malicious URL in the mosConfig_absolute_path parameter.