CVE-2006-5739

Leicestershire communityPortals 1.0 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-5739. PoCs published by Nima Salehi.

AI-analyzed exploit summary This exploit targets a remote file include vulnerability in CommunityPortals <= 1.0 by injecting a remote shell script via the 'cp_root_path' parameter. It allows arbitrary command execution by fetching and executing commands from an attacker-controlled server.

Description

PHP remote file inclusion vulnerability in cpadmin/cpa_index.php in Leicestershire communityPortals 1.0_2005-10-18_12-31-18 allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter, a different vector than CVE-2006-5280.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Nima Salehi · perlwebappsphp
https://www.exploit-db.com/exploits/2516

This exploit targets a remote file include vulnerability in CommunityPortals <= 1.0 by injecting a remote shell script via the 'cp_root_path' parameter. It allows arbitrary command execution by fetching and executing commands from an attacker-controlled server.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: CommunityPortals <= 1.0
No auth needed
Prerequisites: Attacker-controlled server hosting a shell script · Network access to the target web server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017047
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/29487

Scores

EPSS 0.0209
EPSS Percentile 79.2%

Details

Status published
Products (1)
leicestershire/communityportals 1.0
Published Nov 06, 2006
Tracked Since Feb 18, 2026