CVE-2006-7146

Cuttlefish Leicestershire Communityportals < 1.0 - Code Injection

Title source: rule

Description

PHP remote file inclusion vulnerability in bug.php in Leicestershire communityPortals 1.0 build 20051018 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter, a different vector than CVE-2006-5280. NOTE: CVE disputes this issue, since bug.php is not in communityPortals source distributions

Exploits (1)

exploitdb WORKING POC VERIFIED
by Nima Salehi · perlwebappsphp
https://www.exploit-db.com/exploits/28786

Scores

EPSS 0.0377
EPSS Percentile 88.1%

Details

CWE
CWE-94
Status published
Products (1)
cuttlefish/leicestershire_communityportals < 1.0
Published Mar 07, 2007
Tracked Since Feb 18, 2026