peter bassill · operator
$ cve CVE-2006-0147 JSON

CVE-2006-0147 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 13.1% (pctl 96)

Patch early

A public exploit exists.

Description

Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to execute arbitrary PHP functions via the do parameter, which is saved in a variable that is then executed as a function, as demonstrated using phpinfo.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS13.07% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2006-01-09
Last modified2026-06-16

Affected (5)

VendorProduct
john limadodb
mantismantis
moodlemoodle
postnuke software foundationpostnuke
the cacti groupcacti

Public exploits

SourceTitleDate
exploit-dbSimplog 0.9.2 - 's' Remote Command Execution2006-04-11

References

→ the Explorer  ·  watch your stack  ·  NVD