peter bassill · operator
$ cve CVE-2006-0887 JSON

CVE-2006-0887 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 3.5% (pctl 89)

Patch early

A public exploit exists.

Description

Eval injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a, when index.php3 from the PHPLib distribution is available on the server, allows remote attackers to execute arbitrary PHP code by including a base64-encoded representation of the code in a cookie. NOTE: this description was significantly updated on 20060605 to reflect new details after an initial vague advisory.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS3.45% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2006-02-25
Last modified2026-06-16

Affected (1)

VendorProduct
phplib teamphplib

Public exploits

SourceTitleDate
exploit-dbPHPLib < 7.4 - SQL Injection2016-03-05

References

→ the Explorer  ·  watch your stack  ·  NVD