CVE-2006-1551

PAJAX <0.5.1 - Code Injection

Title source: llm

Description

Eval injection vulnerability in pajax_call_dispatcher.php in PAJAX 0.5.1 and earlier allows remote attackers to execute arbitrary code via the (1) $method and (2) $args parameters.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/16901
metasploit WORKING POC EXCELLENT
rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/pajax_remote_exec.rb

Scores

EPSS 0.7215
EPSS Percentile 98.8%

Details

Status published
Products (2)
georges_auberger/pajax 0.5.0
georges_auberger/pajax 0.5.1
Published Apr 13, 2006
Tracked Since Feb 18, 2026