CVE-2006-3363
UnknownEPSS 3.25%
Last modified
CVE-2006-3363 is a vulnerability of currently unknown severity. PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the pa parameter.. EPSS estimates a 3.25% chance of exploitation in the next 30 days.
Description
PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the pa parameter.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xoops | Xoops Glossaire Module | 1.7 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-3363?
PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the pa parameter.
How severe is CVE-2006-3363?
Severity scoring for CVE-2006-3363 is pending analysis. The EPSS model estimates a 3.25% probability of exploitation in the next 30 days.
How do I fix CVE-2006-3363?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-3357Heap-based buffer overflow in HTML Help ActiveX control (hhc…
- CVE-2006-3358Multiple cross-site scripting (XSS) vulnerabilities in index…
- CVE-2006-3359Multiple SQL injection vulnerabilities in index.php in NewsP…
- CVE-2006-3360Directory traversal vulnerability in index.php in phpSysInfo…
- CVE-2006-3361PHP remote file inclusion vulnerability in Stud.IP 1.3.0-2 a…
- CVE-2006-3362Unrestricted file upload vulnerability in connectors/php/con…
- CVE-2006-3364SQL injection vulnerability in index.php in the NP_SEO plugi…
- CVE-2006-3365V3 Chat allows remote attackers to obtain the installation p…
- CVE-2006-3366Multiple cross-site scripting (XSS) vulnerabilities in V3 Ch…
- CVE-2006-3367Mp3 JudeBox Server (Mp3NetBox) Beta 1 stores config.inc unde…
- CVE-2006-3368Efone 20000723 stores config.inc under the web document root…
- CVE-2006-3369Kamikaze-QSCM 0.1 stores config.inc under the web document r…
Are you affected by CVE-2006-3363?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
