CVE-2006-4749

PHP Advanced Transfer Manager <1.20 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-4749. PoCs published by KinSize.

AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in phpAtm <= v1.21 due to improper input validation in the 'include_location' parameter. The exploit allows an attacker to include and execute arbitrary remote PHP code by manipulating the parameter in multiple scripts (confirm.php, index.php, login.php).

Description

Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpATM) 1.20 allow remote attackers to execute arbitrary PHP code via the include_location parameter in (1) activate.php, (2) configure.php, (3) fileop.php, (4) getimg.php, (5) ipblocked.php, (6) register.php, (7) showrecent.php, (8) showtophits.php, (9) usrmanag.php, (10) viewer_bottom.php, (11) viewer_content.php, and (12) viewer_top.php. NOTE: The login.php and confirm.php vectors are already covered by CVE-2006-4594.

Exploits (1)

exploitdb WORKING POC VERIFIED
by KinSize · textwebappsphp
https://www.exploit-db.com/exploits/2279

This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in phpAtm <= v1.21 due to improper input validation in the 'include_location' parameter. The exploit allows an attacker to include and execute arbitrary remote PHP code by manipulating the parameter in multiple scripts (confirm.php, index.php, login.php).

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: phpAtm <= v1.21
No auth needed
Prerequisites: Remote PHP shell or malicious PHP script hosted on an attacker-controlled server · Network access to the vulnerable phpAtm application
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/445742/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/28874

Scores

EPSS 0.0213
EPSS Percentile 79.6%

Details

Status published
Products (1)
bugada_andrea/php_advanced_transfer_manager 1.20
Published Sep 13, 2006
Tracked Since Feb 18, 2026