PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[AA_INC_PATH] parameter in (1) cached.php3, (2) cron.php3, (3) discussion.php3, (4) filldisc.php3, (5) filler.php3, (6) fillform.php3, (7) go.php3, (8) hiercons.php3, (9) jsview.php3, (10) live_checkbox.php3, (11) offline.php3, (12) post2shtml.php3, (13) search.php3, (14) slice.php3, (15) sql_update.php3, (16) view.php3, (17) multiple files in the (18) admin/ folder, (19) includes folder, and (20) modules/ folder
Published May 31, 2006
6.4
MEDIUMCVSS 2.0
EPSS 13.63%
Description
PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[AA_INC_PATH] parameter in (1) cached.php3, (2) cron.php3, (3) discussion.php3, (4) filldisc.php3, (5) filler.php3, (6) fillform.php3, (7) go.php3, (8) hiercons.php3, (9) jsview.php3, (10) live_checkbox.php3, (11) offline.php3, (12) post2shtml.php3, (13) search.php3, (14) slice.php3, (15) sql_update.php3, (16) view.php3, (17) multiple files in the (18) admin/ folder, (19) includes folder, and (20) modules/ folder.
Affected products
No data.
- 2.8.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 13.63% (0.13625) | 96.36th | v5 (v2026.06.15) |
| Jun 15, 2026 | 13.38% (0.13382) | 95.92th | v5 (v2026.06.15) |
| Aug 3, 2025 | 9.89% (0.09893) | 92.73th | v4 (v2025.03.14) |
| Mar 30, 2025 | 11.31% (0.11308) | 92.90th | v4 (v2025.03.14) |
| Mar 29, 2025 | 13.25% (0.13245) | 90.23th | v4 (v2025.03.14) |
| Mar 17, 2025 | 11.31% (0.11308) | 93.00th | v4 (v2025.03.14) |
| Dec 17, 2024 | 44.36% (0.44359) | 97.44th | v3 (v2023.03.01) |
| Sep 19, 2024 | 25.01% (0.25013) | 96.76th | v3 (v2023.03.01) |
| Apr 20, 2024 | 21.96% (0.21956) | 96.40th | v3 (v2023.03.01) |
| Feb 4, 2024 | 17.43% (0.17427) | 95.66th | v3 (v2023.03.01) |
| Dec 11, 2023 | 18.52% (0.18525) | 95.71th | v3 (v2023.03.01) |
| Oct 24, 2023 | 11.92% (0.11916) | 94.70th | v3 (v2023.03.01) |
| Sep 4, 2023 | 16.39% (0.16387) | 95.32th | v3 (v2023.03.01) |
| May 12, 2023 | 12.27% (0.12273) | 94.55th | v3 (v2023.03.01) |
| Apr 4, 2023 | 9.18% (0.09183) | 93.67th | v3 (v2023.03.01) |
| Mar 7, 2023 | 2.97% (0.02972) | 89.32th | v3 (v2023.03.01) |
| Mar 6, 2023 | 15.27% (0.15272) | 95.95th | v2 (v2022.01.01) |
| Apr 1, 2022 | 15.27% (0.15272) | 95.58th | v2 (v2022.01.01) |
| Feb 4, 2022 | 15.27% (0.15272) | 91.38th | v2 (v2022.01.01) |
References (61)
- http://secunia.com/advisories/20299 third-party-advisoryx_refsource_SECUNIAExploitVendor Advisory
- http://www.osvdb.org/27253 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27254 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27256 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27257 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27258 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27259 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27260 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27261 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27262 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27263 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27264 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27265 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27266 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27267 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27268 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27269 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27270 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27271 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27272 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27273 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27274 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27275 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27276 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27277 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27278 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27279 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27280 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27281 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27282 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27283 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27284 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27285 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27286 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27287 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27288 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27289 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27290 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27291 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27292 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27293 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27294 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27295 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27296 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27297 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27298 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27299 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27300 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27301 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27302 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27303 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27304 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27305 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27306 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27308 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27309 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/27310 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/19133 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2006/1997 vdb-entryx_refsource_VUPEN
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26776 vdb-entryx_refsource_XF
- https://www.exploit-db.com/exploits/1829 exploitx_refsource_EXPLOIT-DB
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/20299 | third-party-advisoryx_refsource_SECUNIAExploitVendor Advisory | |
| http://www.osvdb.org/27253 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27254 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27256 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27257 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27258 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27259 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27260 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27261 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27262 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27263 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27264 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27265 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27266 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27267 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27268 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27269 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27270 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27271 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27272 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27273 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27274 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27275 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27276 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27277 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27278 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27279 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27280 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27281 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27282 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27283 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27284 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27285 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27286 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27287 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27288 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27289 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27290 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27291 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27292 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27293 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27294 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27295 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27296 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27297 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27298 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27299 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27300 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27301 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27302 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27303 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27304 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27305 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27306 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27308 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27309 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/27310 | vdb-entryx_refsource_OSVDB | |
| http://www.securityfocus.com/bid/19133 | vdb-entryx_refsource_BID | |
| http://www.vupen.com/english/advisories/2006/1997 | vdb-entryx_refsource_VUPEN | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/26776 | vdb-entryx_refsource_XF | |
| https://www.exploit-db.com/exploits/1829 | exploitx_refsource_EXPLOIT-DB |
Change history (0)
No recorded changes yet.