CVE-2006-4026

Redgraphic Sapid Cms - Code Injection

Title source: rule

Description

PHP remote file inclusion vulnerability in SAPID CMS 123 rc3 allows remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter in usr/extensions/get_infochannel.inc.php and the (2) GLOBALS["root_path"] parameter in usr/extensions/get_tree.inc.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Kacper · textwebappsphp
https://www.exploit-db.com/exploits/2128

Scores

EPSS 0.2090
EPSS Percentile 95.5%

Classification

CWE
CWE-94
Status draft

Affected Products (1)

redgraphic/sapid_cms

Timeline

Published Aug 09, 2006
Tracked Since Feb 18, 2026