peter bassill · operator
$ cve CVE-2006-6661 JSON

CVE-2006-6661 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 6.7% (pctl 94)

Patch early

A public exploit exists.

Description

Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code via multiple vectors that use the extract function, as demonstrated by the (1) f, (2) newmessage, (3) newusername, (4) adminuser, and (5) permission parameters.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS6.66% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2006-12-20
Last modified2026-06-16

Affected (1)

VendorProduct
php-updatephp-update

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD