CVE-2006-2860

Webspotblogging 3.0.1 - RCE

Title source: llm

Description

PHP remote file inclusion vulnerability in Webspotblogging 3.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) inc/logincheck.inc.php, (2) inc/adminheader.inc.php, (3) inc/global.php, or (4) inc/mainheader.inc.php. NOTE: some of these vectors were also reported for 3.0 in a separate disclosure.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Kacper · textwebappsphp
https://www.exploit-db.com/exploits/1871

Scores

EPSS 0.0831
EPSS Percentile 92.1%

Classification

CWE
CWE-94
Status draft

Affected Products (2)

webspot/webspotblogging
webspot/webspotblogging

Timeline

Published Jun 06, 2006
Tracked Since Feb 18, 2026