RULE(RULE ID:336387)

Rule General Information
Release Date: 2022-03-28
Rule Name: CBSMS Mambo Remote File Inclusion Vulnerability (CVE-2006-3294)
Severity:
CVE ID:
Rule Protection Details
Description: PHP remote file inclusion vulnerability in mod_cbsms_messages.php in CBSMS Mambo Module 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: SecurityFocusBID:18660
ExploitDB:1955
http://www.vupen.com/english/advisories/2006/2528
https://exchange.xforce.ibmcloud.com/vulnerabilities/27374
Solutions
Please contact the software vendor to update the software patch.