CVE-2006-6878

PHP-Update <2.7 - Privilege Escalation

Title source: llm

Description

admin/uploads.php in PHP-Update 2.7 and earlier allows remote attackers to gain privileges by setting the rights[7] parameter to 1 during a login action.

Exploits (1)

exploitdb WORKING POC VERIFIED
by undefined1_ · perlwebappsphp
https://www.exploit-db.com/exploits/3020

Scores

EPSS 0.0721
EPSS Percentile 91.6%

Details

Status published
Products (1)
php-update/php-update < 2.7
Published Dec 31, 2006
Tracked Since Feb 18, 2026