CVE-2006-1478
Estado: ModificadaAlta (7.5)—
Directory traversal vulnerability in (1) initiate.php and (2) possibly other PHP scripts in Turnkey Web Tools PHP Live Helper 1.8, and possibly later versions, allows remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the language cookie, as demonstrated by uploading PHP code in a gl_session cookie to users.php, which causes the code to be stored in error.log, which is then included by initiate.php.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.98%
- Percentil entre todas las CVEs puntuadas: 80
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://secunia.com/advisories/19428
- http://securityreason.com/securityalert/641
- http://www.securityfocus.com/archive/1/428976/100/0/threaded
- http://www.turnkeywebtools.com/forum/showthread.php?p=10415
- http://www.worlddefacers.de/Public/WD-TMPLH.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25489
- http://secunia.com/advisories/19428
- http://securityreason.com/securityalert/641
- http://www.securityfocus.com/archive/1/428976/100/0/threaded
- http://www.turnkeywebtools.com/forum/showthread.php?p=10415
- http://www.worlddefacers.de/Public/WD-TMPLH.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25489
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-1478",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": true,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-03-29T01:06:00.000",
"references": [
{
"url": "http://secunia.com/advisories/19428",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/641",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/428976/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.turnkeywebtools.com/forum/showthread.php?p=10415",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.worlddefacers.de/Public/WD-TMPLH.txt",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/25489",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/19428",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/641",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/428976/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.turnkeywebtools.com/forum/showthread.php?p=10415",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.worlddefacers.de/Public/WD-TMPLH.txt",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/25489",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Directory traversal vulnerability in (1) initiate.php and (2) possibly other PHP scripts in Turnkey Web Tools PHP Live Helper 1.8, and possibly later versions, allows remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the language cookie, as demonstrated by uploading PHP code in a gl_session cookie to users.php, which causes the code to be stored in error.log, which is then included by initiate.php."
}
],
"lastModified": "2026-06-16T22:22:45.223",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:turnkey_web_tools:php_live_helper:1.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9C93ED5E-E1D4-4956-8D16-1FF270F1F7AE"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org",
"evaluatorSolution": "This vulnerability may affect all other versions of Turnkey Web Tools, PHP Live Helper."
}