First published: Sat Aug 26 2006(Updated: )
** DISPUTED ** PHP remote file inclusion vulnerability in contxtd.class.php in the Contacts XTD (ContXTD) component for Mambo (com_contxtd) allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: another researcher has disputed this issue, saying that the software prevents the attack by checking whether _VALID_MOS is defined.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mambo Contacts Xtd Component | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-4375 is considered to be high due to the potential for remote code execution.
To mitigate CVE-2006-4375, ensure that the software is updated to a patched version that addresses the vulnerability.
CVE-2006-4375 affects instances of the Mambo CMS that utilize the Contacts XTD component.
Yes, CVE-2006-4375 can allow attackers to execute arbitrary PHP code, potentially leading to unauthorized access.
While CVE-2006-4375 is older, any unpatched software may still be vulnerable and pose a security risk.