CVE-2006-5832 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 3% (pctl 87)
Patch early
A public exploit exists.
Description
All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to obtain the full path of the web server via certain requests to (1) public/code/cp_dpage.php, possibly involving the aiocp_dp[] parameter, (2) public/code/cp_show_ec_products.php, possibly involving the order_field[] parameter, and (3) public/code/cp_show_page_help.php, possibly involving the hp[] parameter, which reveal the path in various error messages.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 3.01% — more likely to be exploited than 87% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-11-10 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| aiocp | aiocp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | AIOCP 1.3.x - Multiple Vulnerabilities | 2006-11-06 |
| exploit-db | AIOCP 1.3.x - 'cp_show_ec_products.php' Full Path Disclosure | 2006-11-06 |
| exploit-db | AIOCP 1.3.x - 'cp_show_page_help.php' Full Path Disclosure | 2006-11-06 |
References
- http://securityreason.com/securityalert/1839
- http://sourceforge.net/project/shownotes.php?release_id=478370
- http://www.securityfocus.com/archive/1/450701/100/0/threaded
- http://www.securityfocus.com/bid/20931
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30052
- http://securityreason.com/securityalert/1839
- http://sourceforge.net/project/shownotes.php?release_id=478370
- http://www.securityfocus.com/archive/1/450701/100/0/threaded
- http://www.securityfocus.com/bid/20931
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30052
→ the Explorer · watch your stack · NVD