Unrated severityNVD Advisory· Published Aug 22, 2006· Updated Apr 16, 2026
CVE-2006-4288
CVE-2006-4288
Description
PHP remote file inclusion vulnerability in admin.a6mambocredits.php in the a6mambocredits component (com_a6mambocredits) 2.0.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. NOTE: some of these details are obtained from third party information.
Affected products
1- cpe:2.3:a:mambo:a6mambocredits_component:2.0.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- secunia.com/advisories/21540nvdExploitVendor Advisory
- securitytracker.com/idnvdExploit
- www.securityfocus.com/bid/19581nvdExploit
- www.osvdb.org/27991nvd
- www.vupen.com/english/advisories/2006/3311nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/28443nvd
- www.exploit-db.com/exploits/2207nvd
News mentions
0No linked articles in our index yet.