CVE-2006-2122

CoolMenus - Remote File Inclusion via Page Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-2122. PoCs published by botan.

AI-analyzed exploit summary This exploit targets a remote file inclusion vulnerability in CoolMenus, allowing an attacker to include and execute arbitrary PHP code from a remote server. The PoC provides a form to input the target URL, command shell URL, and command to execute.

Description

PHP remote file inclusion vulnerability in index.php in CoolMenus allows remote attackers to execute arbitrary code via a URL in the page parameter. NOTE: the original report for this issue is probably erroneous, since CoolMenus does not appear to be written in PHP.

Exploits (1)

exploitdb WORKING POC VERIFIED
by botan · phpwebappsphp
https://www.exploit-db.com/exploits/27768

This exploit targets a remote file inclusion vulnerability in CoolMenus, allowing an attacker to include and execute arbitrary PHP code from a remote server. The PoC provides a form to input the target URL, command shell URL, and command to execute.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: CoolMenus (version not specified)
No auth needed
Prerequisites: Target server with CoolMenus installed and vulnerable to RFI · Remote command shell accessible via URL
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/432630/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/823
Various Sources x_refsource_misc
http://www.dhtmlcentral.com/projects/coolmenus/
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/432395/100/0/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/432597/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17738

Scores

EPSS 0.0430
EPSS Percentile 89.9%

Details

CWE
CWE-94
Status published
Products (1)
coolmenus/coolmenus 4.0
Published May 01, 2006
Tracked Since Feb 18, 2026