CVE-2006-2668

Docebo LMS <2.05 - Remote Code Execution

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-2668. PoCs published by beford.

AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Docebo LMS 2.05, where user-controlled input via the 'lang' parameter is directly included without sanitization. The PoC shows how an attacker can include remote or local files by manipulating the 'lang' parameter.

Description

Multiple PHP remote file inclusion vulnerabilities in Docebo LMS 2.05 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) modules/credits/business.php, (2) modules/credits/credits.php, or (3) modules/credits/help.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by beford · textwebappsphp
https://www.exploit-db.com/exploits/1828

This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Docebo LMS 2.05, where user-controlled input via the 'lang' parameter is directly included without sanitization. The PoC shows how an attacker can include remote or local files by manipulating the 'lang' parameter.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Docebo LMS 2.05
No auth needed
Prerequisites: Access to the vulnerable Docebo LMS instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/1828
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20298
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/435110/30/4710/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/26685
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1978
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18110
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016159

Scores

EPSS 0.0384
EPSS Percentile 88.7%

Details

Status published
Products (1)
docebolms/docebolms 2.0.5
Published May 30, 2006
Tracked Since Feb 18, 2026