Remote File Inclusion Vulnerability in Redaxo CMS by Redaxo
CVE-2006-2845
Currently unrated
What is CVE-2006-2845?
A remote file inclusion vulnerability exists in Redaxo CMS versions 3.0 to 3.2. This flaw allows malicious attackers to execute arbitrary PHP code on the server by exploiting the REX[INCLUDE_PATH] parameter in the image_resize/pages/index.inc.php file. When payloads are injected into this parameter, an attacker can potentially gain unauthorized access and control over the vulnerable system, which compromises its security and integrity.