** DISPUTED ** PHP remote file inclusion vulnerability in handlers/email/mod.output.php in PHlyMail Lite 3.4.4 and earlier (Build 3.04.04) allows remote attackers to execute arbitrary PHP code via a URL in the _PM_[path][handler] parameter, a different vector than CVE-2006-4291. NOTE: This issue has been disputed by a third party, who states that the _IN_PHM_ declaration prevents this file from being called directly.
References
Configurations
History
21 Nov 2024, 00:15
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=115629049105999&w=2 - | |
References | () http://www.osvdb.org/29355 - | |
References | () http://www.securityfocus.com/archive/1/444215/100/0/threaded - Exploit |
Information
Published : 2006-08-29 00:04
Updated : 2025-04-03 01:03
NVD link : CVE-2006-4429
Mitre link : CVE-2006-4429
CVE.ORG link : CVE-2006-4429
JSON object : View
Products Affected
phlymail
- phlymail_lite
CWE