CVE-2006-7146
Cuttlefish Leicestershire Communityportals < 1.0 - Code Injection
Title source: ruleDescription
PHP remote file inclusion vulnerability in bug.php in Leicestershire communityPortals 1.0 build 20051018 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter, a different vector than CVE-2006-5280. NOTE: CVE disputes this issue, since bug.php is not in communityPortals source distributions
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Nima Salehi · perlwebappsphp
https://www.exploit-db.com/exploits/28786
Scores
EPSS
0.0377
EPSS Percentile
88.1%
Details
CWE
CWE-94
Status
published
Products (1)
cuttlefish/leicestershire_communityportals
< 1.0
Published
Mar 07, 2007
Tracked Since
Feb 18, 2026