CVE-2006-6764 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 2.1% (pctl 81)
Patch early
A public exploit exists.
Description
PHP remote file inclusion vulnerability in authenticate.php in Keep It Simple Guest Book (KISGB), when executing PHP through CGI, allows remote attackers to execute arbitrary PHP code via a URL in the default_path_to_themes parameter.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 2.13% — more likely to be exploited than 81% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-12-27 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| keep it simple guest book | keep it simple guest book |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | KISGB 5.1.1 - 'Authenticate.php' Remote File Inclusion | 2006-12-22 |
References
- http://secunia.com/advisories/23477
- http://www.securityfocus.com/bid/21721
- http://www.vupen.com/english/advisories/2006/5147
- https://www.exploit-db.com/exploits/2979
- http://secunia.com/advisories/23477
- http://www.securityfocus.com/bid/21721
- http://www.vupen.com/english/advisories/2006/5147
- https://www.exploit-db.com/exploits/2979
→ the Explorer · watch your stack · NVD