CVE-2006-4418 EXPLOIT
4.0
MEDIUM · CVSS 2.0 · EPSS 2.7% (pctl 85)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in index.php for Wikepage 2006.2a Opus 10 allows remote attackers to include arbitrary local files via the lng parameter, as demonstrated by inserting PHP code into a log file.
Scoring
| CVSS | 4.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:N |
| EPSS | 2.67% — more likely to be exploited than 85% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-08-28 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| wikepage | wikepage |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Wikepage Opus 10 < 2006.2a (lng) - Remote Command Execution | 2006-08-24 |
References
- http://secunia.com/advisories/21542
- http://www.osvdb.org/28177
- http://www.securityfocus.com/bid/19694
- http://www.vupen.com/english/advisories/2006/3386
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28555
- https://www.exploit-db.com/exploits/2252
- http://secunia.com/advisories/21542
- http://www.osvdb.org/28177
- http://www.securityfocus.com/bid/19694
- http://www.vupen.com/english/advisories/2006/3386
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28555
- https://www.exploit-db.com/exploits/2252
→ the Explorer · watch your stack · NVD