First published: Thu Dec 14 2006(Updated: )
PHP remote file inclusion vulnerability in admin/plugins/NP_UserSharing.php in BLOG:CMS 4.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DIR_ADMIN parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Php Blog Cms | =4.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6552 is considered a high-severity vulnerability due to its potential for remote code execution.
To fix CVE-2006-6552, upgrade to BLOG:CMS version 4.1.4 or later, which includes patches for this vulnerability.
CVE-2006-6552 affects all versions of BLOG:CMS up to and including 4.1.3.
CVE-2006-6552 is a remote file inclusion vulnerability that allows attackers to exploit the DIR_ADMIN parameter.
Yes, CVE-2006-6552 can be exploited remotely, allowing attackers to execute arbitrary PHP code.