CVE-2006-4837

EXPLOITED

DCP-Portal SE 6.0 - Remote File Inclusion via Root Parameter

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2006-4837 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Federico Fazzi.

AI-analyzed exploit summary The advisory describes a remote command execution vulnerability in DCP-Portal 6.1.x due to an unsanitized $root variable in lib.php. The PoC demonstrates how an attacker can manipulate the $root variable to execute arbitrary commands via URL injection.

Description

Multiple PHP remote file inclusion vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) library/lib.php and (2) library/editor/editor.php. NOTE: the same primary issue can be used for full path disclosure with an invalid parameter that reveals the installation path in an error message.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Federico Fazzi · textwebappsphp
https://www.exploit-db.com/exploits/1905

The advisory describes a remote command execution vulnerability in DCP-Portal 6.1.x due to an unsanitized $root variable in lib.php. The PoC demonstrates how an attacker can manipulate the $root variable to execute arbitrary commands via URL injection.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: DCP-Portal 6.1.x
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/445996/100/0/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/437510/100/200/threaded
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20024
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1585
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/1905

Scores

EPSS 0.0132
EPSS Percentile 80.4%

Details

VulnCheck KEV 2025-11-10
Status published
Products (1)
codeworx_technologies/dcp-portal se_6.0
Published Sep 15, 2006
Tracked Since Feb 18, 2026