Security Advisory

CVE-2006-5730

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2006-11-06 18:00:00
Last updated 2024-08-07 20:04:54
Assigner mitre
State PUBLISHED

Description

PHP remote file inclusion vulnerability in manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php in Modx CMS 0.9.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter. NOTE: it is possible that this is a vulnerability in FCKeditor.