Unrated severityNVD Advisory· Published Aug 17, 2006· Updated Apr 16, 2026
CVE-2006-4195
CVE-2006-4195
Description
PHP remote file inclusion vulnerability in param.peoplebook.php in the Peoplebook Component for Mambo (com_peoplebook) 1.0 and earlier, and possibly 1.1.2, when register_globals and allow_url_fopen are enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Affected products
2cpe:2.3:a:mamboxchange:peoplebook:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mamboxchange:peoplebook:*:*:*:*:*:*:*:*range: <=1.1.2
- cpe:2.3:a:mamboxchange:peoplebook:1.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.securityfocus.com/bid/19505nvdExploit
- secunia.com/advisories/21470nvdVendor Advisory
- www.vupen.com/english/advisories/2006/3277nvdVendor Advisory
- securityreason.com/securityalert/1406nvd
- www.securityfocus.com/archive/1/443201/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/28359nvd
- www.exploit-db.com/exploits/2184nvd
News mentions
0No linked articles in our index yet.