peter bassill · operator
$ cve CVE-2006-2182 JSON

CVE-2006-2182 EXPLOIT

6.4
MEDIUM · CVSS 2.0 · EPSS 7.6% (pctl 94)

Patch early

A public exploit exists.

Description

Multiple PHP remote file inclusion vulnerabilities in (1) eday.php, (2) eshow.php, or (3) forgot.php in albinator 2.0.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the Config_rootdir parameter.

Scoring

CVSS6.4 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS7.59% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2006-05-04
Last modified2026-06-16

Affected (1)

VendorProduct
albinatoralbinator

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD