CVE-2006-2122

Coolmenus - Code Injection

Title source: rule

Description

PHP remote file inclusion vulnerability in index.php in CoolMenus allows remote attackers to execute arbitrary code via a URL in the page parameter. NOTE: the original report for this issue is probably erroneous, since CoolMenus does not appear to be written in PHP.

Exploits (1)

exploitdb WORKING POC VERIFIED
by botan · phpwebappsphp
https://www.exploit-db.com/exploits/27768

Scores

EPSS 0.0681
EPSS Percentile 91.4%

Details

CWE
CWE-94
Status published
Products (1)
coolmenus/coolmenus 4.0
Published May 01, 2006
Tracked Since Feb 18, 2026