CVE-2006-6225

GeekLog 1.4 - Remote Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-6225. PoCs published by Kw3[R]Ln.

AI-analyzed exploit summary This is a writeup describing a remote file inclusion vulnerability in GeekLog <= 1.4.0 due to unsanitized $_CONF[path] variable when register_globals is enabled. It provides multiple exploit URLs but no actual exploit code.

Description

Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a URL in the _CONF[path] parameter to (1) links/functions.inc, (2) polls/functions.inc, (3) spamx/BlackList.Examine.class.php, (4) spamx/DeleteComment.Action.class.php, (5) spamx/EditIPofURL.Admin.class.php, (6) spamx/MTBlackList.Examine.class.php, (7) spamx/MassDelete.Admin.class.php, (8) spamx/MailAdmin.Action.class.php, (9) spamx/MassDelTrackback.Admin.class.php, (10) spamx/EditHeader.Admin.class.php, (11) spamx/EditIP.Admin.class.php, (12) spamx/IPofUrl.Examine.class.php, (13) spamx/Import.Admin.class.php, (14) spamx/LogView.Admin.class.php, and (15) staticpages/functions.inc, in the plugins/ directory.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Kw3[R]Ln · textwebappsphp
https://www.exploit-db.com/exploits/1963

This is a writeup describing a remote file inclusion vulnerability in GeekLog <= 1.4.0 due to unsanitized $_CONF[path] variable when register_globals is enabled. It provides multiple exploit URLs but no actual exploit code.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: GeekLog <= 1.4.0
No auth needed
Prerequisites: register_globals=on · access to vulnerable GeekLog installation
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27469
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18740
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/1963

Scores

EPSS 0.0419
EPSS Percentile 89.6%

Details

Status published
Products (6)
geeklog/geeklog 1.4.0
geeklog/geeklog 1.4.0_beta1
geeklog/geeklog 1.4.0_sr1
geeklog/geeklog 1.4.0_sr2
geeklog/geeklog 1.4.0_sr3
geeklog/geeklog 1.4.0_sr4
Published Dec 02, 2006
Tracked Since Feb 18, 2026