CVE-2006-3966

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
01/08/2006
Last modified:
03/04/2025

Description

PHP remote file inclusion vulnerability in /lib/tree/layersmenu.inc.php in the PHP Layers Menu 2.3.5 package for MyNewsGroups :) 0.6b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myng_root parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:carlos_sanchez_valle:mynewsgroups:*:*:*:*:*:*:*:* 0.6b (including)
cpe:2.3:a:php_layers_menu:php_layers_menu:2.3.5:*:*:*:*:*:*:*