peter bassill · operator
$ cve CVE-2006-1959 JSON

CVE-2006-1959 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 13.1% (pctl 96)

Patch early

A public exploit exists.

Description

PHP remote file inclusion vulnerability in direct.php in ActualScripts ActualAnalyzer Lite 2.72 and earlier, Gold 7.63 and earlier, and Server 8.23 and earlier allows remote attackers to execute arbitrary code via a URL in the rf parameter.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS13.09% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2006-04-21
Last modified2026-06-16

Affected (1)

VendorProduct
actualscriptsactualanalyzer

Public exploits

SourceTitleDate
exploit-dbActualAnalyzer Server 8.23 - 'rf' Remote File Inclusion2006-05-08

References

→ the Explorer  ·  watch your stack  ·  NVD