CVE-2006-5234
Last modified
CVE-2006-5234 is a vulnerability of currently unknown severity. Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPWS_SOURCE_DIR parameter in (1) init.php, (2) users.php, (3) Cookie.php, (4) forms.php, (5) Groups.php, (6) ModSetting.php, (7) Calendar.php, (8) DateTime.php, (9) core.php, (10) ImgLibrary.php, (11) Manager.php, and (12) Template.php, and (13) EZform.php. NOTE: CVE disputes this report, since "PHPWS_SOURCE_DIR" is defined as a constant, not accessed as a variable. EPSS estimates a 2.68% chance of exploitation in the next 30 days.
Description
Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPWS_SOURCE_DIR parameter in (1) init.php, (2) users.php, (3) Cookie.php, (4) forms.php, (5) Groups.php, (6) ModSetting.php, (7) Calendar.php, (8) DateTime.php, (9) core.php, (10) ImgLibrary.php, (11) Manager.php, and (12) Template.php, and (13) EZform.php. NOTE: CVE disputes this report, since "PHPWS_SOURCE_DIR" is defined as a constant, not accessed as a variable
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Phpwebsite | Phpwebsite | 0.10.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-5234?
How severe is CVE-2006-5234?
How do I fix CVE-2006-5234?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-5228Multiple SQL injection vulnerabilities in the Google Gadget …
- CVE-2006-5229OpenSSH portable 4.1 on SUSE Linux, and possibly other platf…
- CVE-2006-5230PHP remote file inclusion vulnerability in forum.php in Free…
- CVE-2006-5231Grandstream GXP-2000 VoIP Desktop Phone, firmware version 1.…
- CVE-2006-5232Multiple PHP remote file inclusion vulnerabilities in iSearc…
- CVE-2006-5233Polycom SoundPoint IP 301 VoIP Desktop Phone, firmware versi…
- CVE-2006-5235PHP remote file inclusion vulnerability in includes/function…
- CVE-2006-5236SQL injection vulnerability in search.php in 4images 1.7.x a…
- CVE-2006-5237SQL injection vulnerability in Blue Smiley Organizer before …
- CVE-2006-5238Unspecified vulnerability in the file upload module in Blue …
- CVE-2006-5239Multiple cross-site scripting (XSS) vulnerabilities in eXpBl…
- CVE-2006-5240PHP remote file inclusion vulnerability in engine/require.ph…
Are you affected by CVE-2006-5234?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
