Multiple PHP Remote File Inclusion Vulnerabilities in Content*Builder by ContentBuilder
CVE-2006-3173

Currently unrated

Key Information:

Vendor
CVE Published:
23 June 2006

What is CVE-2006-3173?

Content*Builder version 0.7.5 is susceptible to multiple PHP remote file inclusion vulnerabilities. These vulnerabilities allow remote attackers to exploit the system and execute arbitrary PHP code by manipulating specific parameters in the URL. The affected parameters include the path[cb] parameter in libraries/comment/postComment.php and modules/poll/poll.php, the rel parameter in modules/archive/overview.inc.php, and the actualModuleDir parameter in modules/forum/showThread.inc.php. Successful exploitation of these vulnerabilities can lead to unauthorized access and control of the affected server.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.