{
    "id": "CVE-2006-2686",
    "published": "2006-05-31 10:06:00",
    "last_modified": "2026-06-16 22:25:31",
    "cvss_score": "6.4",
    "cvss_severity": "MEDIUM",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
    "cwe": "CWE-94",
    "description": "PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[AA_INC_PATH] parameter in (1) cached.php3, (2) cron.php3, (3) discussion.php3, (4) filldisc.php3, (5) filler.php3, (6) fillform.php3, (7) go.php3, (8) hiercons.php3, (9) jsview.php3, (10) live_checkbox.php3, (11) offline.php3, (12) post2shtml.php3, (13) search.php3, (14) slice.php3, (15) sql_update.php3, (16) view.php3, (17) multiple files in the (18) admin/ folder, (19) includes folder, and (20) modules/ folder.",
    "epss_score": "0.13625",
    "epss_percentile": "0.96351",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-27 18:17:05",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "actionapps",
            "product": "actionapps"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "1829",
            "title": "APC ActionApps CMS 2.8.1 - Remote File Inclusion",
            "date": "2006-05-25",
            "url": "https://www.exploit-db.com/exploits/1829"
        }
    ],
    "refs_list": [
        "http://secunia.com/advisories/20299",
        "http://www.osvdb.org/27253",
        "http://www.osvdb.org/27254",
        "http://www.osvdb.org/27256",
        "http://www.osvdb.org/27257",
        "http://www.osvdb.org/27258",
        "http://www.osvdb.org/27259",
        "http://www.osvdb.org/27260",
        "http://www.osvdb.org/27261",
        "http://www.osvdb.org/27262",
        "http://www.osvdb.org/27263",
        "http://www.osvdb.org/27264",
        "http://www.osvdb.org/27265",
        "http://www.osvdb.org/27266",
        "http://www.osvdb.org/27267",
        "http://www.osvdb.org/27268",
        "http://www.osvdb.org/27269",
        "http://www.osvdb.org/27270",
        "http://www.osvdb.org/27271",
        "http://www.osvdb.org/27272",
        "http://www.osvdb.org/27273",
        "http://www.osvdb.org/27274",
        "http://www.osvdb.org/27275",
        "http://www.osvdb.org/27276",
        "http://www.osvdb.org/27277"
    ]
}