CVE-2006-0725

Plume-cms Plume Cms - Code Injection

Title source: rule

Description

PHP remote file inclusion vulnerability in prepend.php in Plume CMS 1.0.2, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the _PX_config[manager_path] parameter. NOTE: this is a different executable and affected version than CVE-2006-2645.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/1832

Scores

EPSS 0.0532
EPSS Percentile 90.1%

Details

CWE
CWE-94
Status published
Products (1)
plume-cms/plume_cms 1.0.2
Published Feb 16, 2006
Tracked Since Feb 18, 2026