CVE-2006-1013

SMartBlog 1.2 - RCE

Title source: llm
STIX 2.1

Description

PHP remote file include vulnerability in index.php in SMartBlog (aka SMBlog) 1.2 allows remote attackers to include and execute arbitrary PHP files via (1) the pg parameter and (2) a query string without a parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by botan · textwebappsphp
https://www.exploit-db.com/exploits/27340

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/426498/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25220
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16905

Scores

EPSS 0.0336
EPSS Percentile 87.4%

Details

Status published
Products (1)
smartblog/smartblog 1.2
Published Mar 07, 2006
Tracked Since Feb 18, 2026