CVE-2006-1839
PHP Album <0.3.2.3 - RCE
Title source: llmDescription
PHP remote file inclusion vulnerability in language.php in PHP Album 0.3.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary code via an FTP URL in the data_dir parameter, which satisfies the file_exists function call.
Exploits (1)
References (7)
Scores
EPSS
0.0375
EPSS Percentile
88.1%
Details
Status
published
Products (1)
php_album/php_album
0.3.2.3
Published
Apr 19, 2006
Tracked Since
Feb 18, 2026