CVE-2006-6217: High severity PHP-Nuke Mermaid Module vulnerability
PHP remote file inclusion vulnerability in formdisp.php in the Mermaid 1.2 module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the modulename parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6217?
CVE-2006-6217 is considered a critical vulnerability due to its ability to allow remote attackers to execute arbitrary PHP code.
How do I fix CVE-2006-6217?
To fix CVE-2006-6217, update the Mermaid module for PHP-Nuke to a version that is not vulnerable or apply appropriate input validation and sanitization to the module_name parameter.
What systems are affected by CVE-2006-6217?
CVE-2006-6217 specifically affects the Mermaid module version 1.2 of PHP-Nuke.
What type of vulnerability is CVE-2006-6217?
CVE-2006-6217 is classified as a remote file inclusion vulnerability.
How can attackers exploit CVE-2006-6217?
Attackers can exploit CVE-2006-6217 by sending a specially crafted request with a malicious URL in the module_name parameter.