First published: Tue Mar 06 2007(Updated: )
PHP remote file inclusion vulnerability in external/rssfeeds.php in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allows remote attackers to execute arbitrary PHP code via the baseDir parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla BSQ Sitestats | =1.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-7124 has a critical severity level due to potential remote code execution.
To mitigate CVE-2006-7124, upgrade to BSQ Sitestats version 2.2.1 or later.
CVE-2006-7124 affects BSQ Sitestats version 1.8.0 and possibly earlier versions.
CVE-2006-7124 can be exploited through remote file inclusion attacks allowing arbitrary PHP code execution.
CVE-2006-7124 is known to affect Joomla users utilizing the BSQ Sitestats component, making it a notable concern.