CVE-2006-1371 EXPLOIT
9.0
HIGH · CVSS 2.0 · EPSS 9.6% (pctl 95)
Patch early
A public exploit exists.
Description
Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5 and earlier allows remote authenticated users to use the HTMLArea FileManager plugin to upload and execute arbitrary PHP files using (1) manager.php, (2) standalonemanager.php, and (3) images.php.
Scoring
| CVSS | 9.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
| EPSS | 9.61% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-03-23 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| xhp | cms |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | XHP CMS 0.5 - 'upload' Remote Command Execution | 2006-03-22 |
References
- http://secunia.com/advisories/19353
- http://www.attrition.org/pipermail/vim/2006-March/000649.html
- http://www.osvdb.org/24058
- http://www.osvdb.org/24059
- http://www.securityfocus.com/bid/17209
- http://www.vupen.com/english/advisories/2006/1052
- http://xhp.targetit.ro/index.php?page=3&box_id=34&action=show_single_entry&post_id=10
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25399
- https://www.exploit-db.com/exploits/1605
- http://secunia.com/advisories/19353
- http://www.attrition.org/pipermail/vim/2006-March/000649.html
- http://www.osvdb.org/24058
- http://www.osvdb.org/24059
- http://www.securityfocus.com/bid/17209
- http://www.vupen.com/english/advisories/2006/1052
- http://xhp.targetit.ro/index.php?page=3&box_id=34&action=show_single_entry&post_id=10
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25399
- https://www.exploit-db.com/exploits/1605
→ the Explorer · watch your stack · NVD