CVE-2006-5786 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.6% (pctl 85)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in class2.php in e107 0.7.5 and earlier allows remote attackers to read and execute PHP code in arbitrary files via ".." sequences in the e107language_e107cookie cookie to gsitemap.php.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.56% — more likely to be exploited than 85% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-11-07 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| e107 | e107 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | e107 < 0.75 - 'e107language_e107cookie' Local File Inclusion | 2006-11-04 |
References
→ the Explorer · watch your stack · NVD