First published: Tue Oct 24 2006(Updated: )
PHP remote file inclusion vulnerability in lib/rs.php in 2le.net Castor PHP Web Builder 1.1.1 allows remote attackers to execute arbitrary PHP code via the rootpath parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Castor PHP Web Builder | =1.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5480 is considered a critical vulnerability due to its remote file inclusion capability, allowing arbitrary PHP code execution.
To fix CVE-2006-5480, upgrade to a version of Castor PHP Web Builder later than 1.1.1 that does not contain this vulnerability.
CVE-2006-5480 specifically affects Castor PHP Web Builder version 1.1.1.
CVE-2006-5480 is categorized as a remote file inclusion vulnerability.
CVE-2006-5480 can be exploited by attackers who manipulate the rootpath parameter to include malicious PHP code.