CVE-2006-4280: High severity Mambo Anjel Component vulnerability
DISPUTED PHP remote file inclusion vulnerability in anjel.index.php in ANJEL (formerly MaMML) Component (comanjel) for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter. NOTE: this issue has been disputed by a third party, who says that $mosConfigabsolutepath is set in a configuration file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4280?
The severity of CVE-2006-4280 is considered high due to the potential for remote code execution.
How do I fix CVE-2006-4280?
To fix CVE-2006-4280, upgrade to a patched version of the Mambo Anjel Component that addresses this vulnerability.
What type of attacks can be performed due to CVE-2006-4280?
CVE-2006-4280 allows attackers to execute arbitrary PHP code through remote file inclusion.
Which versions of Mambo are affected by CVE-2006-4280?
All versions of the Mambo Anjel Component prior to the fix are potentially affected by CVE-2006-4280.
Is CVE-2006-4280 a confirmed vulnerability?
CVE-2006-4280 has been disputed by a third party, raising questions about its confirmation.