CVE-2006-4837

EXPLOITED

DCP-Portal SE 6.0 - RCE

Title source: llm

Description

Multiple PHP remote file inclusion vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) library/lib.php and (2) library/editor/editor.php. NOTE: the same primary issue can be used for full path disclosure with an invalid parameter that reveals the installation path in an error message.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Federico Fazzi · textwebappsphp
https://www.exploit-db.com/exploits/1905

Scores

EPSS 0.0132
EPSS Percentile 79.9%

Details

VulnCheck KEV 2025-11-10
Status published
Products (1)
codeworx_technologies/dcp-portal se_6.0
Published Sep 15, 2006
Tracked Since Feb 18, 2026