CVE-2006-1839

PHP Album <0.3.2.3 - RCE

Title source: llm

Description

PHP remote file inclusion vulnerability in language.php in PHP Album 0.3.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary code via an FTP URL in the data_dir parameter, which satisfies the file_exists function call.

Exploits (1)

exploitdb WRITEUP VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/27643

Scores

EPSS 0.0375
EPSS Percentile 88.1%

Details

Status published
Products (1)
php_album/php_album 0.3.2.3
Published Apr 19, 2006
Tracked Since Feb 18, 2026