CVE-2006-4004

vbPortal 3.0.2-3.6.0 Beta 1 - Unauthenticated Directory Traversal and Remote Code Execution via bbvbplang Cookie

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-4004. PoCs published by r00t.

AI-analyzed exploit summary This exploit targets a remote command execution vulnerability in vbPortal versions 3.0.2 to 3.6.0 Beta 1 by injecting PHP code into log files via HTTP headers and then triggering execution through a path traversal attack. It requires magic_quotes_gpc to be off and relies on predictable log file locations.

Description

Directory traversal vulnerability in index.php in vbPortal 3.0.2 through 3.6.0 Beta 1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the bbvbplang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by r00t · phpwebappsphp
https://www.exploit-db.com/exploits/2087

This exploit targets a remote command execution vulnerability in vbPortal versions 3.0.2 to 3.6.0 Beta 1 by injecting PHP code into log files via HTTP headers and then triggering execution through a path traversal attack. It requires magic_quotes_gpc to be off and relies on predictable log file locations.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: vbPortal 3.0.2 <= 3.6.0 Beta 1
No auth needed
Prerequisites: magic_quotes_gpc=Off · writable log files · predictable log file paths
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19257
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/2087
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/28077
Exploit, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21287
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3102

Scores

EPSS 0.0288
EPSS Percentile 85.0%

Details

Status published
Products (5)
vbportal/vbportal 3.0.2
vbportal/vbportal 3.5.0_beta_2
vbportal/vbportal 3.5.0_beta_3
vbportal/vbportal 3.5.0_gold
vbportal/vbportal 3.6.0_beta_1
Published Aug 07, 2006
Tracked Since Feb 18, 2026