CVE-2006-4721

CCleague Pro Sports CMS 1.0.1 RC1 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-4721. PoCs published by Kacper.

AI-analyzed exploit summary This exploit targets CVE-2006-4721 in CCleague Pro Sports CMS <= 1.0.1RC1 by injecting arbitrary commands via a maliciously crafted Cookie header. It leverages path traversal to log the command into Apache log files, which are then executed due to improper input validation.

Description

Directory traversal vulnerability in admin.php in CCleague Pro Sports CMS 1.0.1 RC1 allows remote attackers to read and execute arbitrary local files via a .. (dot dot) sequence and trailing null (%00) byte in the language Cookie parameter, as demonstrated by executing PHP code via a log file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Kacper · phpwebappsphp
https://www.exploit-db.com/exploits/2333

This exploit targets CVE-2006-4721 in CCleague Pro Sports CMS <= 1.0.1RC1 by injecting arbitrary commands via a maliciously crafted Cookie header. It leverages path traversal to log the command into Apache log files, which are then executed due to improper input validation.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: CCleague Pro Sports CMS v1.0.1RC1
No auth needed
Prerequisites: register_globals=On · magic_quotes_gpc=Off · Apache log files writable
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21843
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/463217/100/0/threaded
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3549
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/2333
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/463191/100/0/threaded
Various Sources x_refsource_misc
http://unkn0wn.awardspace.com/Blog/?p=46

Scores

EPSS 0.0264
EPSS Percentile 83.6%

Details

Status published
Products (1)
ccleague/pro_sports_cms 1.0.1_rc1
Published Sep 12, 2006
Tracked Since Feb 18, 2026