CVE-2006-5044

Princeclan Chess <0.8 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-5044. PoCs published by OLiBekaS.

AI-analyzed exploit summary This exploit leverages a file inclusion vulnerability in the pc_chess component for Joomla, allowing an attacker to include a remote file containing arbitrary commands. The vulnerability is triggered via the mosConfig_absolute_path parameter.

Description

Unspecified vulnerability in Prince Clan (Princeclan) Chess component (com_pcchess) 0.8 and earlier for Mambo and Joomla! has unspecified impact and attack vectors.

Exploits (1)

exploitdb WORKING POC VERIFIED
by OLiBekaS · textwebappsphp
https://www.exploit-db.com/exploits/2069

This exploit leverages a file inclusion vulnerability in the pc_chess component for Joomla, allowing an attacker to include a remote file containing arbitrary commands. The vulnerability is triggered via the mosConfig_absolute_path parameter.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Joomla! with pc_chess component
No auth needed
Prerequisites: Target must have the vulnerable pc_chess component installed · Remote file inclusion must be enabled on the server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Various Sources x_refsource_confirm
http://www.princeclan.org
Various Sources x_refsource_confirm
http://forum.joomla.org/index.php/topic%2C79477.0.html

Scores

EPSS 0.0193
EPSS Percentile 77.3%

Details

Status published
Products (2)
joomla/prince_clan_chess_component < 0.8
mambo/prince_clan_chess_component < 0.8
Published Sep 27, 2006
Tracked Since Feb 18, 2026