Multiple PHP Remote File Inclusion Vulnerabilities in Content*Builder by Content-Builder
CVE-2006-3172

Currently unrated

Key Information:

Vendor
CVE Published:
23 June 2006

What is CVE-2006-3172?

Content*Builder version 0.7.5 is affected by multiple PHP remote file inclusion vulnerabilities, which can be exploited by remote attackers to execute arbitrary PHP code. These vulnerabilities arise when certain parameters, such as lang_path and path[cb], are improperly sanitized, allowing attackers to craft malicous URLs with trailing slashes. Exploits can target specific plugins and modules within the CMS, including the column management, polling, user management, and media management functionalities. As a result, unauthorized execution of PHP code can occur, leading to potential system compromise and data exposure.

References

EPSS Score

15% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.