CVE Database
/

CVE-2006-4264

Back to search

CVE-2006-4264

Published: Aug 21, 2006

Modified: Jan 17, 2025

PUBLISHED

Description

Multiple PHP remote file inclusion vulnerabilities in the lmtg_myhomepage Component (com_lmtg_myhomepage) for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) install.lmtg_homepage.php and (2) mtg_homepage.php. NOTE: this issue has been disputed by a third party, who states that the $mosConfig_absolute_path variable is only used within a function definition. CVE source code analysis on 20060824 is not conclusive but tends to concur with the dispute. In addition, it appears that the component name is actually "lmtg_myhomepage"

VendorProductVersions

n/a

n/a

affected
n/a

References

28087
vdb-entry
x_refsource_OSVDB
19584
vdb-entry
x_refsource_BID
28088
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now