peter bassill · operator
$ cve CVE-2006-6809 JSON

CVE-2006-6809 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.4% (pctl 84)

Patch early

A public exploit exists.

Description

Multiple PHP remote file inclusion vulnerabilities in process.php in Vladimir Menshakov buratinable templator (aka bubla) 1.0.0rc2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) bu_dir or (2) bu_config[dir] parameter.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.43% — more likely to be exploited than 84% of all CVEs
On CISA KEVno
Public exploityes
Published2006-12-29
Last modified2026-06-16

Affected (1)

VendorProduct
vladimir menshakovburatinable templator

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD