First published: Thu Oct 26 2006(Updated: )
Multiple PHP remote file inclusion vulnerabilities in AROUNDMe 0.6.9, and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the templatePath parameter in template/barnraiser_01/pol_view.tpl.php and other unspecified PHP scripts, a different vector than CVE-2006-5401.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
barnraiser AROUNDMe | <=0.6.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-5533 is considered high due to its potential to allow remote code execution.
To fix CVE-2006-5533, disable register_globals in your PHP configuration and upgrade to a patched version of AROUNDMe.
Affected versions of AROUNDMe for CVE-2006-5533 are 0.6.9 and possibly earlier versions.
CVE-2006-5533 allows remote attackers to execute arbitrary PHP code on the server.
CVE-2006-5533 manifests in various PHP scripts, including template/barnraiser_01/pol_view.tpl.php.