CVE-2006-5730: Medium severity Modxcms Modxcms vulnerability
PHP remote file inclusion vulnerability in manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php in Modx CMS 0.9.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the basepath parameter. NOTE: it is possible that this is a vulnerability in FCKeditor.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5730?
CVE-2006-5730 is considered a critical vulnerability as it allows remote code execution through remote file inclusion.
How do I fix CVE-2006-5730?
To fix CVE-2006-5730, upgrade Modx CMS to version 0.9.2.2 or later, which addresses this vulnerability.
What type of attack does CVE-2006-5730 facilitate?
CVE-2006-5730 facilitates remote code execution attacks by allowing attackers to include and execute arbitrary PHP code.
What versions of Modx CMS are affected by CVE-2006-5730?
Modx CMS versions 0.9.1 and earlier than 0.9.2.2 are affected by CVE-2006-5730.
Can CVE-2006-5730 be exploited without authentication?
Yes, CVE-2006-5730 can be exploited without authentication, making it particularly dangerous.