First published: Thu Oct 12 2006(Updated: )
PHP remote file inclusion vulnerability in modules/forum/include/config.php in Ciamos Content Management System (CMS) 0.9.6b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_cache_path parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ciamos CMS | <=0.9.6b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5257 is classified as a critical vulnerability due to its potential to allow remote code execution.
To resolve CVE-2006-5257, upgrade to a version of Ciamos CMS later than 0.9.6b, where the vulnerability is patched.
CVE-2006-5257 affects Ciamos CMS versions 0.9.6b and earlier.
Attackers can exploit CVE-2006-5257 by injecting a malicious URL into the module_cache_path parameter, leading to remote code execution.
CVE-2006-5257 is a remote file inclusion (RFI) vulnerability.