CVE-2006-1371

Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5 - Authenticated RCE

Title source: llm

Description

Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5 and earlier allows remote authenticated users to use the HTMLArea FileManager plugin to upload and execute arbitrary PHP files using (1) manager.php, (2) standalonemanager.php, and (3) images.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1605

Scores

EPSS 0.0885
EPSS Percentile 92.6%

Details

CWE
CWE-94
Status published
Products (1)
xhp/cms < 0.5
Published Mar 23, 2006
Tracked Since Feb 18, 2026