CVE-2006-5135: High severity a-blog a-blog vulnerability
Multiple PHP remote file inclusion vulnerabilities in A-Blog 2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) openbox, (2) middlebox, and (3) closebox parameters in (a) sources/myaccount.php; the (4) navigationend parameter in (b) navigation/search.php and (c) navigation/donation.php; and the (6) navigationstart and (7) navigationmiddle parameters in navigation/donation.php, (d) navigation/latestnews.php, and (e) navigation/links.php; different vectors than CVE-2006-5092.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5135?
CVE-2006-5135 is a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2006-5135?
To fix CVE-2006-5135, upgrade A-Blog to a version that addresses these remote file inclusion vulnerabilities.
What systems are affected by CVE-2006-5135?
CVE-2006-5135 affects A-Blog version 2, specifically via certain parameters in multiple PHP files.
What type of vulnerability is CVE-2006-5135?
CVE-2006-5135 is classified as a remote file inclusion vulnerability.
Can CVE-2006-5135 lead to unauthorized server access?
Yes, CVE-2006-5135 can lead to unauthorized access as it allows attackers to execute arbitrary PHP code on the server.