CVE-2006-6796

MTCMS <2.0 - RCE

Title source: llm

Description

PHP remote file inclusion vulnerability in admin/admin_settings.php in MTCMS 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ins_file parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by nuffsaid · perlwebappsphp
https://www.exploit-db.com/exploits/3005

Scores

EPSS 0.0669
EPSS Percentile 91.3%

Details

Status published
Products (1)
mtcms/mtcms < 2.0
Published Dec 28, 2006
Tracked Since Feb 18, 2026