peter bassill · operator
$ cve CVE-2006-4969 JSON

CVE-2006-4969 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 12.1% (pctl 96)

Patch early

A public exploit exists.

Description

Multiple PHP remote file inclusion vulnerabilities in WAHM E-Commerce Pie Cart Pro allow remote attackers to execute arbitrary PHP code via a URL in the Inc_Dir parameter in (1) affiliates.php, (2) orders.php, (3) events.php, (4) index.php, (5) articles.php, (6) faqs.php, (7) guestbook.php, (8) catalog.php, (9) wholesale.php, (10) weblinks.php, (11) certificates.php, (12) sitesearch.php, (13) contact.php, (14) sitemap.php, (15) search.php, (16) registry.php, or (17) error.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS12.09% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2006-09-25
Last modified2026-06-16

Affected (1)

VendorProduct
wahm e-commercepie cart pro

Public exploits

SourceTitleDate
exploit-dbPie Cart Pro - 'Inc_Dir' Remote File Inclusion2006-09-19

References

→ the Explorer  ·  watch your stack  ·  NVD