Unrated severityNVD Advisory· Published Sep 26, 2006· Updated Jun 16, 2026
CVE-2006-4992
CVE-2006-4992
Description
Multiple PHP remote file inclusion vulnerabilities in JD-WordPress for Joomla! (com_jd-wp) 2.0-1.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) wp-comments-post.php, (2) wp-feed.php, or (3) wp-trackback.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:joomla:jd-wordpress:2.0.1.0_rc2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:joomla:jd-wordpress:2.0.1.0_rc2:*:*:*:*:*:*:*
- (no CPE)range: = 2.0-1.0 RC2
Patches
Vulnerability mechanics
References
7- www.babilonics.comnvdExploit
- www.osvdb.org/28997nvdExploit
- www.osvdb.org/28998nvdExploit
- www.osvdb.org/28999nvdExploit
- www.securityfocus.com/bid/19209nvdExploit
- forum.joomla.org/index.php/topic%2C79477.0.htmlnvd
- forum.joomla.org/index.php/topic%2C81064.0.htmlnvd
News mentions
0No linked articles in our index yet.