U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2006-4264

Change History

CVE Modified by MITRE 11/06/2023 8:59:15 PM

Action Type Old Value New Value
Changed Description
** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in the lmtg_myhomepage Component (com_lmtg_myhomepage) for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) install.lmtg_homepage.php and (2) mtg_homepage.php.  NOTE: this issue has been disputed by a third party, who states that the $mosConfig_absolute_path variable is only used within a function definition.  CVE source code analysis on 20060824 is not conclusive but tends to concur with the dispute.  In addition, it appears that the component name is actually "lmtg_myhomepage".
Multiple PHP remote file inclusion vulnerabilities in the lmtg_myhomepage Component (com_lmtg_myhomepage) for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) install.lmtg_homepage.php and (2) mtg_homepage.php.  NOTE: this issue has been disputed by a third party, who states that the $mosConfig_absolute_path variable is only used within a function definition.  CVE source code analysis on 20060824 is not conclusive but tends to concur with the dispute.  In addition, it appears that the component name is actually "lmtg_myhomepage"