CVE-2006-5243

OpenDock Easy Doc < 1.4 - Remote File Inclusion via doc_directory Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-5243.

AI-analyzed exploit summary The advisory details a remote file inclusion vulnerability in OpenDock Easy Doc <=1.4, where the '$doc_directory' parameter in multiple PHP scripts is not properly sanitized, allowing arbitrary PHP code execution via external file inclusion. Proof-of-concept URLs are provided to demonstrate exploitation.

Description

Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Doc 1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) down_stat.php, (2) file.php, (3) find_file.php, (4) lib_file.php, and (5) lib_form_file.php in sw/lib_up_file/; (6) find_comment.php, (7) comment.php, and (8) lib_comment.php in sw/lib_comment/; (9) sw/lib_find/find.php; and other unspecified PHP scripts.

Exploits (1)

exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/2494

The advisory details a remote file inclusion vulnerability in OpenDock Easy Doc <=1.4, where the '$doc_directory' parameter in multiple PHP scripts is not properly sanitized, allowing arbitrary PHP code execution via external file inclusion. Proof-of-concept URLs are provided to demonstrate exploitation.

Classification
Writeup 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: OpenDock Easy Doc <=1.4
No auth needed
Prerequisites: Network access to the target application · Ability to host a malicious PHP file on an external server
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/29404
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1715
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3971
Exploit vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017022
Exploit, Vendor Advisory x_refsource_misc
http://advisories.echo.or.id/adv/adv49-theday-2006.txt
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20407
Exploit, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22334
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/448010/100/0/threaded

Scores

EPSS 0.0350
EPSS Percentile 87.7%

Details

Status published
Products (1)
opendock/easy_doc < 1.4
Published Oct 12, 2006
Tracked Since Feb 18, 2026