Back

MEDIUM

PHP remote file inclusion vulnerability in SmartSiteCMS 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the root parameter in (1) comment.php, (2) admin/comedit.php, (3) admin/test.php, (4) admin/index.php, and (5) admin/include/inc_adminfoot.php, a different set of vectors than CVE-2006-3162

Published Jul 7, 2006

Description

PHP remote file inclusion vulnerability in SmartSiteCMS 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the root parameter in (1) comment.php, (2) admin/comedit.php, (3) admin/test.php, (4) admin/index.php, and (5) admin/include/inc_adminfoot.php, a different set of vectors than CVE-2006-3162.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Jul 7, 2006
Updated Aug 7, 2024
Reserved Jul 6, 2006

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 16, 2026

Red Hat

No data

ENISA EUVD

Assigner mitre
Published Jul 7, 2006
Updated Aug 7, 2024

GitHub

No data