CVE-2006-5234: High severity phpwebsite phpwebsite vulnerability
DISPUTED Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPWSSOURCEDIR parameter in (1) init.php, (2) users.php, (3) Cookie.php, (4) forms.php, (5) Groups.php, (6) ModSetting.php, (7) Calendar.php, (8) DateTime.php, (9) core.php, (10) ImgLibrary.php, (11) Manager.php, and (12) Template.php, and (13) EZform.php. NOTE: CVE disputes this report, since "PHPWSSOURCEDIR" is defined as a constant, not accessed as a variable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5234?
CVE-2006-5234 is considered to be a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2006-5234?
To fix CVE-2006-5234, it is recommended to upgrade phpWebSite to a version that does not contain this vulnerability.
What software is affected by CVE-2006-5234?
CVE-2006-5234 specifically affects phpWebSite version 0.10.2.
Can CVE-2006-5234 allow attackers to execute arbitrary code?
Yes, CVE-2006-5234 allows remote attackers to execute arbitrary PHP code through the PHPWS_SOURCE_DIR parameter.
Is CVE-2006-5234 a remote file inclusion vulnerability?
Yes, CVE-2006-5234 is classified as a remote file inclusion vulnerability.