CVE-2006-5234
Estado: ModificadaAlta (7.5)—
Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPWS_SOURCE_DIR parameter in (1) init.php, (2) users.php, (3) Cookie.php, (4) forms.php, (5) Groups.php, (6) ModSetting.php, (7) Calendar.php, (8) DateTime.php, (9) core.php, (10) ImgLibrary.php, (11) Manager.php, and (12) Template.php, and (13) EZform.php. NOTE: CVE disputes this report, since "PHPWS_SOURCE_DIR" is defined as a constant, not accessed as a variable
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.77%
- Percentil entre todas las CVEs puntuadas: 86
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://securityreason.com/securityalert/1716
- http://www.attrition.org/pipermail/vim/2006-October/001079.html
- http://www.securityfocus.com/archive/1/448098/100/0/threaded
- http://www.securityfocus.com/archive/1/448307/100/100/threaded
- http://www.securityfocus.com/bid/20412
- http://securityreason.com/securityalert/1716
- http://www.attrition.org/pipermail/vim/2006-October/001079.html
- http://www.securityfocus.com/archive/1/448098/100/0/threaded
- http://www.securityfocus.com/archive/1/448307/100/100/threaded
- http://www.securityfocus.com/bid/20412
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-5234",
"cveTags": [
{
"tags": [
"disputed"
],
"sourceIdentifier": "cve@mitre.org"
}
],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-10-11T01:07:00.000",
"references": [
{
"url": "http://securityreason.com/securityalert/1716",
"source": "cve@mitre.org"
},
{
"url": "http://www.attrition.org/pipermail/vim/2006-October/001079.html",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/448098/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/448307/100/100/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/20412",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/1716",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.attrition.org/pipermail/vim/2006-October/001079.html",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/448098/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/448307/100/100/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/20412",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPWS_SOURCE_DIR parameter in (1) init.php, (2) users.php, (3) Cookie.php, (4) forms.php, (5) Groups.php, (6) ModSetting.php, (7) Calendar.php, (8) DateTime.php, (9) core.php, (10) ImgLibrary.php, (11) Manager.php, and (12) Template.php, and (13) EZform.php. NOTE: CVE disputes this report, since \"PHPWS_SOURCE_DIR\" is defined as a constant, not accessed as a variable"
},
{
"lang": "es",
"value": "** IMPUGNADO ** Múltiples vulnerabilidades de inclusión remota de archivo en PHP en phpWebSite 0.10.2 permiten a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro PHPWS_SOURCE_DIR en (1) init.php, (2) users.php, (3) Cookie.php, (4) forms.php, (5) Groups.php, (6) ModSetting.php, (7) Calendar.php, (8) DateTime.php, (9) core.php, (10) ImgLibrary.php, (11) Manager.php, (12) Template.php, y (13) EZform.php. NOTA: CVE impugna este informe, ya que \"PHPWS_SOURCE_DIR\" está definido como una constante, no accesible como una variable."
}
],
"lastModified": "2026-06-16T22:30:48.253",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:phpwebsite:phpwebsite:0.10.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5F5A8763-F36A-4FF6-8BD2-8CC2B4250BA7"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}