CVE-2006-1839

PHP Album 0.3.2.3 - Remote File Inclusion via language.php data_dir Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-1839. PoCs published by rgod.

AI-analyzed exploit summary This is a writeup describing a remote file-include vulnerability in phpAlbum 0.3.2.3 and prior versions. It lacks actual exploit code but details the vulnerability and its impact.

Description

PHP remote file inclusion vulnerability in language.php in PHP Album 0.3.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary code via an FTP URL in the data_dir parameter, which satisfies the file_exists function call.

Exploits (1)

exploitdb WRITEUP VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/27643

This is a writeup describing a remote file-include vulnerability in phpAlbum 0.3.2.3 and prior versions. It lacks actual exploit code but details the vulnerability and its impact.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: phpAlbum <= 0.3.2.3
No auth needed
Prerequisites: A vulnerable version of phpAlbum · Ability to send crafted HTTP requests to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1382
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19661
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17526
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25846
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/24741
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/431067/100/0/threaded

Scores

EPSS 0.0565
EPSS Percentile 92.0%

Details

Status published
Products (1)
php_album/php_album 0.3.2.3
Published Apr 19, 2006
Tracked Since Feb 18, 2026