CVE-2006-2811
Last modified
CVE-2006-2811 is a vulnerability of currently unknown severity. Multiple PHP remote file inclusion vulnerabilities in Cantico Ovidentia 5.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the babInstallPath parameter in (1) index.php, (2) topman.php, (3) approb.php, (4) vacadmb.php, (5) vacadma.php, (6) vacadm.php, (7) statart.php, (8) search.php, (9) posts.php, (10) options.php, (11) login.php, (12) frchart.php, (13) flbchart.php, (14) fileman.php, (15) faq.php, (16) event.php, (17) directory.php, (18) articles.php, (19) artedit.php, (20) calday.php, and additional unspecified PHP scripts. NOTE: the utilit.php vector is already covered by CVE-2005-1964.. EPSS estimates a 17.08% chance of exploitation in the next 30 days.
Description
Multiple PHP remote file inclusion vulnerabilities in Cantico Ovidentia 5.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the babInstallPath parameter in (1) index.php, (2) topman.php, (3) approb.php, (4) vacadmb.php, (5) vacadma.php, (6) vacadm.php, (7) statart.php, (8) search.php, (9) posts.php, (10) options.php, (11) login.php, (12) frchart.php, (13) flbchart.php, (14) fileman.php, (15) faq.php, (16) event.php, (17) directory.php, (18) articles.php, (19) artedit.php, (20) calday.php, and additional unspecified PHP scripts. NOTE: the utilit.php vector is already covered by CVE-2005-1964.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cantico | Ovidentia | 5.8.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-2811?
How severe is CVE-2006-2811?
How do I fix CVE-2006-2811?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-2805SQL injection vulnerability in VBulletin 3.0.10 allows remot…
- CVE-2006-2806The SMTP server in Apache Java Mail Enterprise Server (aka A…
- CVE-2006-2807ASPwebSoft Speedy Asp Discussion Forum allows remote attacke…
- CVE-2006-2808Cross-site scripting (XSS) vulnerability in Lycos Tripod htm…
- CVE-2006-2809Multiple cross-site scripting (XSS) vulnerabilities in index…
- CVE-2006-2810Multiple cross-site scripting (XSS) vulnerabilities in Belch…
- CVE-2006-2812Multiple cross-site scripting (XSS) vulnerabilities in index…
- CVE-2006-2813Directory traversal vulnerability in easy-scart.cgi in iShop…
- CVE-2006-2814Multiple buffer overflows in the (1) vGetPost and (2) main f…
- CVE-2006-2815Multiple cross-site scripting (XSS) vulnerabilities in Two S…
- CVE-2006-2816Multiple cross-site scripting (XSS) vulnerabilities in index…
- CVE-2006-2817SQL injection vulnerability in bolum.php in tekno.Portal all…
Are you affected by CVE-2006-2811?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
