Vulnerability Description
Multiple PHP remote file inclusion vulnerabilities in phpMyAgenda 3.0 Final and earlier allow remote attackers to execute arbitrary PHP code via a URL in the rootagenda parameter to (1) agendaplace.php3, (2) agendaplace2.php3, (3) infoevent.php3, and (4) agenda2.php3, different vectors than CVE-2006-2009.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpmyagenda | Phpmyagenda | <= 3.0_final |
References
- http://osvdb.org/ref/29/2914x-phpmyagenda.txt
- http://sourceforge.net/forum/forum.php?forum_id=569237Patch
- http://www.osvdb.org/29148Patch
- http://www.osvdb.org/29149Patch
- http://www.osvdb.org/29150Patch
- http://www.osvdb.org/29151Patch
- http://www.securityfocus.com/archive/1/433995
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26062
- http://osvdb.org/ref/29/2914x-phpmyagenda.txt
- http://sourceforge.net/forum/forum.php?forum_id=569237Patch
- http://www.osvdb.org/29148Patch
- http://www.osvdb.org/29149Patch
- http://www.osvdb.org/29150Patch
- http://www.osvdb.org/29151Patch
- http://www.securityfocus.com/archive/1/433995
FAQ
What is CVE-2006-5132?
CVE-2006-5132 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple PHP remote file inclusion vulnerabilities in phpMyAgenda 3.0 Final and earlier allow remote attackers to execute arbitrary PHP code via a URL in the rootagenda parameter to (1) agendaplace.ph...
How severe is CVE-2006-5132?
CVE-2006-5132 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-5132?
Check the references section above for vendor advisories and patch information. Affected products include: Phpmyagenda Phpmyagenda.