CVE-2006-4418

Wikepage 2006.2a Opus 10 - Directory Traversal via lng Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-4418. PoCs published by Hessam-x.

AI-analyzed exploit summary This exploit targets a PHP code injection vulnerability in WIKEPAGE <= V2006.2a. It injects malicious PHP code into the server's log files via HTTP headers and then executes arbitrary commands by including the log file.

Description

Directory traversal vulnerability in index.php for Wikepage 2006.2a Opus 10 allows remote attackers to include arbitrary local files via the lng parameter, as demonstrated by inserting PHP code into a log file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Hessam-x · perlwebappsphp
https://www.exploit-db.com/exploits/2252

This exploit targets a PHP code injection vulnerability in WIKEPAGE <= V2006.2a. It injects malicious PHP code into the server's log files via HTTP headers and then executes arbitrary commands by including the log file.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WIKEPAGE <= V2006.2a
No auth needed
Prerequisites: Target server running WIKEPAGE <= V2006.2a · Access to the target server's web interface · Knowledge of common Apache log file paths
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/28555
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/2252
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/28177
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21542
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3386
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19694

Scores

EPSS 0.0261
EPSS Percentile 83.4%

Details

Status published
Products (2)
wikepage/wikepage 2006.2
wikepage/wikepage 2006.2a
Published Aug 28, 2006
Tracked Since Feb 18, 2026