First published: Fri Dec 15 2006(Updated: )
PHP remote file inclusion vulnerability in includes/profilcp_constants.php in the Profile Control Panel (CPanel) module for mxBB 0.91c allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mxbb Mxbb Newssuite | =0.91c | |
=0.91c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6566 has a high severity rating due to the potential for remote code execution by attackers.
To fix CVE-2006-6566, upgrade mxBB to a version that does not contain the vulnerable includes/profilcp_constants.php file.
CVE-2006-6566 affects users running mxBB version 0.91c.
CVE-2006-6566 allows attackers to execute arbitrary PHP code through remote file inclusion.
A possible workaround for CVE-2006-6566 is to disable the module which uses the vulnerable includes/profilcp_constants.php file.