First published: Thu Dec 14 2006(Updated: )
PHP remote file inclusion vulnerability in includes/newssuite_constants.php in the NewsSuite 1.03 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mxbb Newssuite | =1.03 | |
=1.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6553 is considered a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2006-6553, upgrade to a version of NewsSuite that is not affected or remove the vulnerable includes/newssuite_constants.php file.
The impact of CVE-2006-6553 allows remote attackers to execute arbitrary PHP code, compromising the security of the affected server.
CVE-2006-6553 affects version 1.03 of the NewsSuite module for mxBB.
There is no specific patch available for CVE-2006-6553; the advised mitigation is to upgrade or remove the vulnerable component.