peter bassill · operator
$ cve CVE-2006-6764 JSON

CVE-2006-6764 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 2.1% (pctl 81)

Patch early

A public exploit exists.

Description

PHP remote file inclusion vulnerability in authenticate.php in Keep It Simple Guest Book (KISGB), when executing PHP through CGI, allows remote attackers to execute arbitrary PHP code via a URL in the default_path_to_themes parameter.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS2.13% — more likely to be exploited than 81% of all CVEs
On CISA KEVno
Public exploityes
Published2006-12-27
Last modified2026-06-16

Affected (1)

VendorProduct
keep it simple guest bookkeep it simple guest book

Public exploits

SourceTitleDate
exploit-dbKISGB 5.1.1 - 'Authenticate.php' Remote File Inclusion2006-12-22

References

→ the Explorer  ·  watch your stack  ·  NVD