CVE-2006-6550: High severity phorum phorum vulnerability
DISPUTED PHP remote file inclusion vulnerability in common.php in Phorum 3.2.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the dbfile parameter. NOTE: CVE disputes this vulnerability because dbfile is defined before use.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6550?
CVE-2006-6550 is classified as a medium severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2006-6550?
To fix CVE-2006-6550, upgrade Phorum to version 3.2.11 or a later release that addresses this vulnerability.
What is CVE-2006-6550?
CVE-2006-6550 is a remote file inclusion vulnerability in Phorum 3.2.11 that can allow attackers to execute arbitrary PHP code.
Who is affected by CVE-2006-6550?
CVE-2006-6550 affects Phorum versions up to and including 3.2.11.
Can CVE-2006-6550 be exploited remotely?
Yes, CVE-2006-6550 can be exploited remotely if an attacker manipulates the db_file parameter.