CVE-2006-5263

Phpmyagenda < 3.1_beta_1 - Path Traversal

Title source: rule

Description

Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter, as demonstrated by a parameter value naming an Apache HTTP Server log file that apparently contains PHP code.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Nima Salehi · perlwebappsphp
https://www.exploit-db.com/exploits/2500

Scores

EPSS 0.0701
EPSS Percentile 91.5%

Details

Status published
Products (1)
phpmyagenda/phpmyagenda < 3.1_beta_1
Published Oct 12, 2006
Tracked Since Feb 18, 2026