CVE-2006-4354: High severity Phome Empire Phome Empire CMS vulnerability
Published Aug 26, 2006
·Updated
PHP remote file inclusion vulnerability in e/class/CheckLevel.php in Phome Empire CMS 3.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the checkpath parameter.
Affected Software
1 affected component
Phome Empire Phome Empire CMS=3.7
Event History
Aug 26, 2006
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4354?
CVE-2006-4354 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2006-4354?
To fix CVE-2006-4354, upgrade Phome Empire CMS to version 3.8 or later.
3
What systems are affected by CVE-2006-4354?
CVE-2006-4354 affects Phome Empire CMS version 3.7 and earlier.
4
What type of vulnerability is CVE-2006-4354?
CVE-2006-4354 is classified as a remote file inclusion vulnerability.
5
How can attackers exploit CVE-2006-4354?
Attackers can exploit CVE-2006-4354 by modifying the check_path parameter to include malicious URLs.