peter bassill · operator
$ cve CVE-2006-5923 JSON

CVE-2006-5923 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.4% (pctl 84)

Patch early

A public exploit exists.

Description

PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the custom parameter.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.43% — more likely to be exploited than 84% of all CVEs
On CISA KEVno
Public exploityes
Published2006-11-15
Last modified2026-06-16

Affected (1)

VendorProduct
chris macgimescripts shopping catalog

Public exploits

SourceTitleDate
exploit-dbgtcatalog 0.9.1 - 'index.php' Remote File Inclusion2006-11-09

References

→ the Explorer  ·  watch your stack  ·  NVD