VYPR
Unrated severityNVD Advisory· Published Aug 8, 2006· Updated Apr 16, 2026

CVE-2006-3584

CVE-2006-3584

Description

Dynamic variable evaluation vulnerability in index.php in Jetbox CMS 2.1 SR1 allows remote attackers to overwrite configuration variables via URL parameters, which are evaluated as PHP variable variables.

Affected products

2
  • Jetbox/Jetbox CMS2 versions
    cpe:2.3:a:jetbox:jetbox_cms:2.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:jetbox:jetbox_cms:2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:jetbox:jetbox_cms:2.1_sr1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.