CVE-2006-6856
WebText CMS <0.4.5.2 - Code Injection
Title source: llmDescription
Direct static code injection vulnerability in WebText CMS 0.4.5.2 and earlier allows remote attackers to inject arbitrary PHP code into a script in wt/users/ via the im parameter during a profile edit (edycja) operation, which is then executed via a direct request for this script.
Exploits (1)
Scores
EPSS
0.0721
EPSS Percentile
91.5%
Classification
Status
draft
Affected Products (1)
webtext/webtext
< 0.4.5.2
Timeline
Published
Dec 31, 2006
Tracked Since
Feb 18, 2026