Multiple PHP Remote File Inclusion Vulnerabilities in Content*Builder by Content-Builder
CVE-2006-3172
Currently unrated
What is CVE-2006-3172?
Content*Builder version 0.7.5 is affected by multiple PHP remote file inclusion vulnerabilities, which can be exploited by remote attackers to execute arbitrary PHP code. These vulnerabilities arise when certain parameters, such as lang_path and path[cb], are improperly sanitized, allowing attackers to craft malicous URLs with trailing slashes. Exploits can target specific plugins and modules within the CMS, including the column management, polling, user management, and media management functionalities. As a result, unauthorized execution of PHP code can occur, leading to potential system compromise and data exposure.
