peter bassill · operator
$ cve CVE-2006-5832 JSON

CVE-2006-5832 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 3% (pctl 87)

Patch early

A public exploit exists.

Description

All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to obtain the full path of the web server via certain requests to (1) public/code/cp_dpage.php, possibly involving the aiocp_dp[] parameter, (2) public/code/cp_show_ec_products.php, possibly involving the order_field[] parameter, and (3) public/code/cp_show_page_help.php, possibly involving the hp[] parameter, which reveal the path in various error messages.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS3.01% — more likely to be exploited than 87% of all CVEs
On CISA KEVno
Public exploityes
Published2006-11-10
Last modified2026-06-16

Affected (1)

VendorProduct
aiocpaiocp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD