CVE-2006-4738: High severity Jetbox Jetbox CMS vulnerability
Published Sep 13, 2006
·Updated
PHP remote file inclusion vulnerability in phpthumb.php in Jetbox CMS allows remote attackers to execute arbitrary PHP code via a URL in the includespath parameter. NOTE: The relativescriptpath vector is already covered by CVE-2006-2270.
Affected Software
1 affected component
Jetbox Jetbox CMS=2.1_sr1
Event History
Sep 13, 2006
CVE Published
10:07 PM
Sep 14, 2006
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4738?
CVE-2006-4738 is rated as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2006-4738?
To fix CVE-2006-4738, it is recommended to update Jetbox CMS to a version that addresses this vulnerability.
3
What systems are affected by CVE-2006-4738?
CVE-2006-4738 affects Jetbox CMS version 2.1_sr1.
4
Can CVE-2006-4738 be exploited remotely?
Yes, CVE-2006-4738 can be exploited remotely by attackers through the includes_path parameter.
5
What kind of attack can CVE-2006-4738 enable?
CVE-2006-4738 can enable attackers to execute arbitrary PHP code on the affected system.