CVE-2006-5923

Chris Mac gtcatalog <0.9.1 - RCE

Title source: llm
STIX 2.1

Description

PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the custom parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by v1per-haCker · textwebappsphp
https://www.exploit-db.com/exploits/2745

References (3)

Core 3
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20979
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/452114/100/200/threaded
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/2745

Scores

EPSS 0.0495
EPSS Percentile 89.7%

Details

Status published
Products (1)
chris_mac/gimescripts_shopping_catalog < 0.9.1
Published Nov 15, 2006
Tracked Since Feb 18, 2026