Remote File Inclusion Vulnerabilities in Redaxo CMS
CVE-2006-2844
Currently unrated
What is CVE-2006-2844?
Redaxo CMS version 3.0 is susceptible to multiple remote file inclusion vulnerabilities. These flaws allow an attacker to execute arbitrary PHP code by injecting a malicious URL into the REX[INCLUDE_PATH] parameter of the affected scripts: simple_user/pages/index.inc.php and stats/pages/index.inc.php. Successful exploitation can lead to a complete compromise of the affected system.