First published: Thu Oct 26 2006(Updated: )
** DISPUTED ** PHP remote file inclusion vulnerability in libraries/amfphp/amf-core/custom/CachedGateway.php in Adobe PHP SDK allows remote attackers to execute arbitrary PHP code via the AMFPHP_BASE parameter. NOTE: this issue has been disputed by a third-party researcher who states that AMFPHP_BASE is a constant.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe PHP RIA SDK | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-5549 is disputed, but it is classified as a remote file inclusion vulnerability that allows arbitrary PHP code execution.
To fix CVE-2006-5549, validate input parameters and configure the application to disable the inclusion of remote files.
CVE-2006-5549 affects Adobe PHP SDK implementations using the CachedGateway.php file.
Yes, if exploited, CVE-2006-5549 can potentially allow attackers to execute arbitrary code, leading to full system compromise.
There is no explicit patch provided for CVE-2006-5549, but mitigating measures should be implemented to secure applications.