Vulnerability Description
PHP remote file inclusion vulnerability in the Enigma2 plugin (Enigma2.php) in Enigma WordPress Bridge allows remote attackers to execute arbitrary PHP code via a URL in the boarddir parameter. NOTE: CVE disputes this issue, since $boarddir is set to a fixed value
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Enigma | Wordpress Bridge | All versions |
References
- http://securityreason.com/securityalert/2093
- http://securitytracker.com/id?017459
- http://www.attrition.org/pipermail/vim/2007-January/001207.html
- http://www.securityfocus.com/archive/1/455555/100/0/threaded
- http://www.securityfocus.com/bid/21826Exploit
- https://www.exploit-db.com/exploits/3051
- http://securityreason.com/securityalert/2093
- http://securitytracker.com/id?017459
- http://www.attrition.org/pipermail/vim/2007-January/001207.html
- http://www.securityfocus.com/archive/1/455555/100/0/threaded
- http://www.securityfocus.com/bid/21826Exploit
- https://www.exploit-db.com/exploits/3051
FAQ
What is CVE-2006-6863?
CVE-2006-6863 is a vulnerability with a CVSS score of 9.8 (CRITICAL). PHP remote file inclusion vulnerability in the Enigma2 plugin (Enigma2.php) in Enigma WordPress Bridge allows remote attackers to execute arbitrary PHP code via a URL in the boarddir parameter. NOTE:...
How severe is CVE-2006-6863?
CVE-2006-6863 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2006-6863?
Check the references section above for vendor advisories and patch information. Affected products include: Enigma Wordpress Bridge.