CVE-2006-4236

POWERGAP - Remote Code Execution

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-4236. PoCs published by Saudi Hackrz.

AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Powergap Shop software (versions <= s0x.php). The vulnerability allows an attacker to include and execute arbitrary remote files via the 'shopid' parameter in multiple PHP scripts (s01.php, s02.php, s03.php, s04.php).

Description

Multiple PHP remote file inclusion vulnerabilities in POWERGAP allow remote attackers to execute arbitrary PHP code via a URL in the (1) shopid parameter to (a) s01.php, (b) s02.php, (c) s03.php, and (d) s04.php; and possibly a URL located after "shopid=" or "sid=" in the PATH_INFO.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Saudi Hackrz · textwebappsphp
https://www.exploit-db.com/exploits/2201

This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Powergap Shop software (versions <= s0x.php). The vulnerability allows an attacker to include and execute arbitrary remote files via the 'shopid' parameter in multiple PHP scripts (s01.php, s02.php, s03.php, s04.php).

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Powergap Shop <= s0x.php
No auth needed
Prerequisites: Remote file inclusion must be enabled on the target server · Attacker must have access to a remote server hosting malicious code
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/29497
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19565
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016715
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1417
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/29498
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/29499
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/443469/100/0/threaded
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/2201
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/29496
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/29500
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/28425

Scores

EPSS 0.0948
EPSS Percentile 94.8%

Details

Status published
Products (2)
powergap/powergap_business
powergap/powergap_lite
Published Aug 21, 2006
Tracked Since Feb 18, 2026