CVE-2006-6592: High severity php bloq vulnerability
Published Dec 15, 2006
·Updated
Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code via a URL in the page[path] parameter to (1) index.php, (2) admin.php, (3) rss.php, (4) rdf.php, (5) rss2.php, or (6) files/mainfile.php.
Affected Software
1 affected component
PHP Bloq=0.5.4
Event History
Dec 15, 2006
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:28 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-6592?
CVE-2006-6592 is considered a critical severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2006-6592?
To fix CVE-2006-6592, upgrade to a version of Bloq that is not vulnerable to remote file inclusion attacks.
3
What are the affected software versions for CVE-2006-6592?
CVE-2006-6592 specifically affects Bloq version 0.5.4.
4
What impact does CVE-2006-6592 have on my system?
CVE-2006-6592 allows attackers to execute arbitrary PHP code on affected systems, potentially leading to a complete compromise.
5
Is CVE-2006-6592 exploitable without authentication?
Yes, CVE-2006-6592 can be exploited remotely without the need for authentication.