peter bassill · operator
$ cve CVE-2006-2928 JSON

CVE-2006-2928 EXPLOIT

5.1
MEDIUM · CVSS 2.0 · EPSS 4.6% (pctl 91)

Patch early

A public exploit exists.

Description

Multiple PHP remote file inclusion vulnerabilities in CMS-Bandits 2.5 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter in (1) dialogs/img.php and (2) dialogs/td.php.

Scoring

CVSS5.1 (MEDIUM, v2.0)
VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
EPSS4.58% — more likely to be exploited than 91% of all CVEs
On CISA KEVno
Public exploityes
Published2006-06-09
Last modified2026-06-16

Affected (1)

VendorProduct
cms-banditscms-bandits

Public exploits

SourceTitleDate
exploit-dbCMS-Bandits 2.5 - 'spaw_root' Remote File Inclusion2006-06-08

References

→ the Explorer  ·  watch your stack  ·  NVD