Vulnerabilities > CVE-2006-4372 - Remote Security vulnerability in Constructor Component

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
constructor-component
exploit available

Summary

PHP remote file inclusion vulnerability in admin.lurm_constructor.php in the Lurm Constructor component (com_lurm_constructor) 0.6b and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the lm_absolute_path parameter.

Vulnerable Configurations

Part Description Count
Application
Constructor_Component
1

Exploit-Db

descriptionMambo com_lurm_constructor Component <= 0.6b Include Vulnerability. CVE-2006-4372. Webapps exploit for php platform
fileexploits/php/webapps/2222.txt
idEDB-ID:2222
last seen2016-01-31
modified2006-08-19
platformphp
port
published2006-08-19
reportermdx
sourcehttps://www.exploit-db.com/download/2222/
titleMambo com_lurm_constructor Component <= 0.6b Include Vulnerability
typewebapps