PHP Remote File Inclusion Vulnerability in Redaxo by Redaxo
CVE-2006-2843

Currently unrated

Key Information:

Vendor

Redaxo

Status
Vendor
CVE Published:
6 June 2006

What is CVE-2006-2843?

A PHP remote file inclusion vulnerability exists in Redaxo 2.7.4, allowing remote attackers to execute arbitrary PHP code. This can be exploited by inserting a malicious URL into the REX[INCLUDE_PATH] parameter found in the addons/import_export/pages/index.inc.php and pages/community.inc.php scripts. Without proper validation, these parameters can be manipulated, leading to potential remote code execution and significant security risks for affected installations.

References

EPSS Score

8% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.