CVE-2006-4987

Wili-CMS - RCE

Title source: llm

Description

Multiple PHP remote file inclusion vulnerabilities in Patrick Michaelis Wili-CMS allow remote attackers to execute arbitrary PHP code via a URL in the globals[content_dir] parameter in (1) example-view/templates/article.php, (2) example-view/templates/root.php, and (3) example-view/templates/dates_list.php.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/2414

Scores

EPSS 0.0216
EPSS Percentile 84.0%

Classification

Status draft

Affected Products (1)

patrick_michaelis/wili-cms

Timeline

Published Sep 26, 2006
Tracked Since Feb 18, 2026