First published: Sun Dec 10 2006(Updated: )
PHP remote file inclusion vulnerability in inc/CONTROL/import/import-mt.php in b2evolution 1.8.5 through 1.9 beta allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Evolution | =1.8.5 | |
Evolution | =1.9 | |
Evolution | =1.9_beta |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6417 is classified as a high-severity vulnerability that allows remote code execution.
To fix CVE-2006-6417, update b2evolution to a patched version beyond 1.9 beta.
CVE-2006-6417 affects b2evolution versions 1.8.5, 1.9, and 1.9 beta.
Exploiting CVE-2006-6417 can allow attackers to execute arbitrary PHP code on the affected server.
Yes, CVE-2006-6417 remains a concern for systems that have not been updated, particularly in legacy environments.