CVE-2006-7079: Path Traversal
Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execute arbitrary code by modifying the $xoopsOption['pagetype'] variable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-7079?
CVE-2006-7079 is considered a critical vulnerability due to its potential for remote code execution and directory traversal attacks.
How do I fix CVE-2006-7079?
To fix CVE-2006-7079, update your exV2 Content Management System to version 2.0.4.4 or later.
What software is affected by CVE-2006-7079?
CVE-2006-7079 affects exV2 Content Management System version 2.0.4.3 and earlier.
Can CVE-2006-7079 lead to data compromise?
Yes, CVE-2006-7079 can allow attackers to overwrite arbitrary variables and execute malicious code, leading to potential data compromise.
Are there any known exploits for CVE-2006-7079?
Yes, there are known exploits for CVE-2006-7079 that leverage the vulnerability to perform unauthorized actions on affected systems.