CVE-2006-5076

OpenConcept Back-End <0.4.5 - RCE

Title source: llm

Description

Multiple PHP remote file inclusion vulnerabilities in OpenConcept Back-End 0.4.5 allow remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter in (1) admin/index.php, (2) Facts.php, or (3) search.php.

Exploits (3)

exploitdb WRITEUP VERIFIED
by Root3r_H3ll · textwebappsphp
https://www.exploit-db.com/exploits/28676
exploitdb WRITEUP VERIFIED
by Root3r_H3ll · textwebappsphp
https://www.exploit-db.com/exploits/28675
exploitdb WORKING POC VERIFIED
by Root3r_H3ll · perlwebappsphp
https://www.exploit-db.com/exploits/28674

Scores

EPSS 0.0372
EPSS Percentile 88.0%

Details

Status published
Products (1)
back-end/back-end_cms 0.4.5
Published Sep 29, 2006
Tracked Since Feb 18, 2026