CVE-2006-1363

Justin White FreeWPS 2.11 - RCE

Title source: llm

Description

images.php in Justin White (aka YTZ) Free Web Publishing System (FreeWPS) 2.11 allows remote attackers to execute arbitrary PHP code by uploading a .php file into the /upload directory as specified in the dirPath parameter, then performing a direct request to that file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by x128 · phpwebappsphp
https://www.exploit-db.com/exploits/1600

Scores

EPSS 0.0573
EPSS Percentile 90.5%

Details

Status published
Products (1)
justin_white/freewps 2.11
Published Mar 23, 2006
Tracked Since Feb 18, 2026