First published: Tue Sep 26 2006(Updated: )
PHP remote file inclusion vulnerability in BSQ Sitestats (bsq_sitestats) before 2.1.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla BSQ Sitestats | =2.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4995 is considered a critical vulnerability as it allows remote attackers to execute arbitrary PHP code.
To fix CVE-2006-4995, update the BSQ Sitestats extension to version 2.1.1 or later.
CVE-2006-4995 affects the BSQ Sitestats extension for Joomla! versions prior to 2.1.1.
The impact of CVE-2006-4995 allows attackers to execute arbitrary code on the server, potentially leading to full compromise of the system.
CVE-2006-4995 can be exploited by remote attackers who can manipulate the mosConfig_absolute_path parameter.