Description
Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php, (4) install.uhp.php, (5) toolbar.uhp.html.php, (6) uhp.class.php, and (7) uninstall.uhp.php, in the UHP (User Home Pages) 0.5 component (aka com_uhp) for Mambo or Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
In plain language
AI Worth attentionCVE-2006-3995 is a Joomla!/Mambo “User Home Pages” (UHP) weakness that lets an attacker run malicious PHP code remotely using a crafted URL; if you use this UHP component, you should act soon.
CVE-2006-3995 is a remote PHP file inclusion flaw in the UHP (User Home Pages) component for Mambo or Joomla! (via a URL parameter such as mosConfig_absolute_path), allowing unauthenticated attackers to execute arbitrary PHP code remotely; public exploits exist, but it is not listed in CISA KEV.
What to do now
- Check whether your site runs the “UHP (User Home Pages)” component for Mambo or Joomla! (for example, look for the com_uhp / UHP component files and pages such as uhp_config.php and uhp.class.php).
- If the UHP component is installed, compare its version against the remediation guidance referenced in Secunia advisory 21305 and OSVDB 27651, and confirm you are on the fixed release per those advisories.
- Immediately apply the vendor remediation referenced in Secunia advisory 21305 (or the OSVDB 27651-linked guidance) if you are currently using a vulnerable UHP version.
- If you cannot patch right away, remove or disable the UHP component until you can apply the remediation.
CVSS Vector Breakdown
AV:NAccess VectorAC:MAccess ComplexityAu:NAuthenticationC:PConfidentialityI:PIntegrityA:PAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2006-3995 and every CVE in our database. Create a free account — no credit card required.
Create Free Account