CVE-2006-4837
EXPLOITEDDCP-Portal SE 6.0 - RCE
Title source: llmDescription
Multiple PHP remote file inclusion vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) library/lib.php and (2) library/editor/editor.php. NOTE: the same primary issue can be used for full path disclosure with an invalid parameter that reveals the installation path in an error message.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Federico Fazzi · textwebappsphp
https://www.exploit-db.com/exploits/1905
References (5)
Scores
EPSS
0.0132
EPSS Percentile
79.9%
Details
VulnCheck KEV
2025-11-10
Status
published
Products (1)
codeworx_technologies/dcp-portal
se_6.0
Published
Sep 15, 2006
Tracked Since
Feb 18, 2026