peter bassill · operator
$ cve CVE-2006-5918 JSON

CVE-2006-5918 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.5% (pctl 84)

Patch early

A public exploit exists.

Description

Unrestricted file upload vulnerability in RapidKill (aka PHP Rapid Kill) 5.7 Pro, and certain other versions, allows remote attackers to upload and execute arbitrary PHP scripts via the "Link to Download" field. NOTE: it is possible that the field value is restricted to files on specific public web sites.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.48% — more likely to be exploited than 84% of all CVEs
On CISA KEVno
Public exploityes
Published2006-11-15
Last modified2026-06-16

Affected (1)

VendorProduct
php rapid killphp rapid kill

Public exploits

SourceTitleDate
exploit-dbPHP RapidKill Pro 5.x - Arbitrary File Upload2010-04-17

References

→ the Explorer  ·  watch your stack  ·  NVD