CVE-2006-6049: High severity phil taylor shambo2 vulnerability
PHP remote file inclusion vulnerability in shambo2.php in the Shambo2 (comshambo2) component for Mambo 4.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6049?
CVE-2006-6049 is considered a critical vulnerability due to the risk of arbitrary PHP code execution.
How do I fix CVE-2006-6049?
To fix CVE-2006-6049, you should update the Shambo2 component to the latest version that patches the remote file inclusion issue.
Which software is affected by CVE-2006-6049?
CVE-2006-6049 affects the Shambo2 component for Mambo 4.5.
Can CVE-2006-6049 be exploited remotely?
Yes, CVE-2006-6049 can be exploited remotely, allowing attackers to execute arbitrary PHP code through a crafted URL.
What is remote file inclusion in the context of CVE-2006-6049?
Remote file inclusion in the context of CVE-2006-6049 refers to the vulnerability that allows an attacker to include files from an external server, leading to potential code execution.