CVE-2006-5533: Medium severity AROUNDMe AROUNDMe vulnerability
Multiple PHP remote file inclusion vulnerabilities in AROUNDMe 0.6.9, and possibly earlier, when registerglobals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the templatePath parameter in template/barnraiser01/polview.tpl.php and other unspecified PHP scripts, a different vector than CVE-2006-5401.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5533?
The severity of CVE-2006-5533 is considered high due to its potential to allow remote code execution.
How do I fix CVE-2006-5533?
To fix CVE-2006-5533, disable register_globals in your PHP configuration and upgrade to a patched version of AROUNDMe.
What are the affected versions of AROUNDMe in CVE-2006-5533?
Affected versions of AROUNDMe for CVE-2006-5533 are 0.6.9 and possibly earlier versions.
What type of attack is possible with CVE-2006-5533?
CVE-2006-5533 allows remote attackers to execute arbitrary PHP code on the server.
In which PHP scripts does CVE-2006-5533 manifest?
CVE-2006-5533 manifests in various PHP scripts, including template/barnraiser_01/pol_view.tpl.php.