Dynamic variable evaluation vulnerability in index.php in Jetbox CMS 2.1 SR1 allows remote attackers to overwrite configuration variables via URL parameters, which are evaluated as PHP variable variables.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:13
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/20889 - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2006-57/advisory/ - Vendor Advisory | |
References | () http://securityreason.com/securityalert/1339 - | |
References | () http://www.securityfocus.com/archive/1/441980/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/19303 - |
Information
Published : 2006-08-08 23:04
Updated : 2024-11-21 00:13
NVD link : CVE-2006-3584
Mitre link : CVE-2006-3584
CVE.ORG link : CVE-2006-3584
JSON object : View
Products Affected
jetbox
- jetbox_cms
CWE