peter bassill · operator
$ cve CVE-2006-3193 JSON

CVE-2006-3193 EXPLOIT

5.1
MEDIUM · CVSS 2.0 · EPSS 14.8% (pctl 97)

Patch early

A public exploit exists.

Description

Multiple PHP remote file inclusion vulnerabilities in Grayscale BandSite CMS 1.1.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) includes/content/contact_content.php; multiple files in adminpanel/includes/add_forms/ including (2) addbioform.php, (3) addfliersform.php, (4) addgenmerchform.php, (5) addinterviewsform.php, (6) addlinksform.php, (7) addlyricsform.php, (8) addmembioform.php, (9) addmerchform.php, (10) addmerchpicform.php, (11) addnewsform.php, (12) addphotosform.php, (13) addreleaseform.php, (14) addreleasepicform.php, (15) addrelmerchform.php, (16) addreviewsform.php, (17) addshowsform.php, (18) addwearmerchform.php; (19) adminpanel/includes/mailinglist/disphtmltbl.php, and (20) adminpanel/includes/mailinglist/dispxls.php.

Scoring

CVSS5.1 (MEDIUM, v2.0)
VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
EPSS14.85% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2006-06-23
Last modified2026-06-16

Affected (1)

VendorProduct
grayscalebandsite cms

Public exploits

SourceTitleDate
exploit-dbBandSite CMS 1.1.1 - 'ROOT_PATH' Remote File Inclusion2006-06-20

References

→ the Explorer  ·  watch your stack  ·  NVD