CVE-2006-1584

Warcraft III Replay Parser for PHP <1.8c - XSS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-1584. PoCs published by botan.

AI-analyzed exploit summary The provided text describes a remote file inclusion vulnerability in Warcraft III Replay Parser for PHP 1.8c, allowing arbitrary remote file inclusion and execution of malicious PHP code. The example URL demonstrates how an attacker could exploit this by including a remote file with a command execution payload.

Description

Unspecified vulnerability in index.php in Warcraft III Replay Parser for PHP 1.8c allows remote attackers to inject arbitrary web script or HTML via the page parameter, possibly related to fopen function calls or file uploads. NOTE: post-disclosure analysis by CVE suggests that the "page" parameter is not used in this product, and "id" might be the affected parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by botan · textwebappsphp
https://www.exploit-db.com/exploits/27537

The provided text describes a remote file inclusion vulnerability in Warcraft III Replay Parser for PHP 1.8c, allowing arbitrary remote file inclusion and execution of malicious PHP code. The example URL demonstrates how an attacker could exploit this by including a remote file with a command execution payload.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: Warcraft III Replay Parser for PHP 1.8c
No auth needed
Prerequisites: A vulnerable version of Warcraft III Replay Parser for PHP · Ability to host a malicious PHP file on a remote server · Network access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/429535/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25686
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17334

Scores

EPSS 0.0586
EPSS Percentile 92.2%

Details

Status published
Products (1)
juliusz_julas_gonera/warcraft_iii_replay_parser_php 1.8c
Published Apr 02, 2006
Tracked Since Feb 18, 2026