peter bassill · operator
$ cve CVE-2006-0881 JSON

CVE-2006-0881 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 7.7% (pctl 94)

Patch early

A public exploit exists.

Description

Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah's Classifieds 1.3, when register_globals is enabled, allow remote attackers to include arbitrary PHP files via the (1) upperTemplate and (2) lowerTemplate parameters, as demonstrated using the lowerTemplate parameter to index.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS7.65% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2006-02-24
Last modified2026-06-16

Affected (1)

VendorProduct
phpoutsourcingnoahs classifieds

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD