CVE-2006-4618: Medium severity john lim adodb vulnerability
Published Sep 7, 2006
·Updated
PHP remote file inclusion vulnerability in adodb-postgres7.inc.php in John Lim ADOdb, possibly 4.01 and earlier, as used in Intechnic In-link 2.3.4, allows remote attackers to execute arbitrary PHP code via a URL in the ADODBDIR parameter.
Affected Software
1 affected component
John Lim adodb<=4.01
Remediation
Event History
Sep 7, 2006
CVE Published
12:04 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4618?
CVE-2006-4618 is considered a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2006-4618?
To fix CVE-2006-4618, upgrade ADOdb to version 4.2 or later.
3
What software is affected by CVE-2006-4618?
CVE-2006-4618 affects ADOdb versions up to and including 4.01.
4
How does CVE-2006-4618 work?
CVE-2006-4618 allows attackers to exploit the ADODB_DIR parameter to include arbitrary remote files.
5
Who is the vendor for the software affected by CVE-2006-4618?
The vendor for the software affected by CVE-2006-4618 is John Lim.