Remote File Inclusion Vulnerabilities in Redaxo CMS
CVE-2006-2844

Currently unrated

Key Information:

Vendor

Redaxo

Status
Vendor
CVE Published:
6 June 2006

What is CVE-2006-2844?

Redaxo CMS version 3.0 is susceptible to multiple remote file inclusion vulnerabilities. These flaws allow an attacker to execute arbitrary PHP code by injecting a malicious URL into the REX[INCLUDE_PATH] parameter of the affected scripts: simple_user/pages/index.inc.php and stats/pages/index.inc.php. Successful exploitation can lead to a complete compromise of the affected system.

References

EPSS Score

8% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.