CVE-2006-1749

phpListPro <2.1 - RCE

Title source: llm

Description

PHP remote file inclusion vulnerability in config.php in phpListPro 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the returnpath parameter. NOTE: this issue was later reported to affect 2.01 as well.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/1769

Scores

EPSS 0.0490
EPSS Percentile 89.6%

Details

CWE
CWE-94
Status published
Products (2)
smartisoft/phplistpro 2.01
smartisoft/phplistpro < 2.0
Published Apr 12, 2006
Tracked Since Feb 18, 2026