CVE-2006-2315

Ispconfig < 2.2.2 - Code Injection

Title source: rule

Description

PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the go_info[server][classes_root] parameter. NOTE: the vendor has disputed this vulnerability, saying that session.inc.php is not under the web root in version 2.2, and register_globals is not enabled

Exploits (1)

exploitdb WORKING POC VERIFIED
by ReZEN · phpwebappsphp
https://www.exploit-db.com/exploits/27845

Scores

EPSS 0.1299
EPSS Percentile 94.1%

Details

CWE
CWE-94
Status published
Products (1)
ispconfig/ispconfig < 2.2.2
Published May 12, 2006
Tracked Since Feb 18, 2026