Multiple PHP remote file inclusion vulnerabilities in Dolphin 5.1 allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter in (1) index.php, (2) aemodule.php, (3) browse.php, (4) cc.php, (5) click.php, (6) faq.php, (7) gallery.php, (8) im.php, (9) inbox.php, (10) join_form.php, (11) logout.php, (12) messages_inbox.php, and many other scripts
Published Aug 17, 2006
5.1
MEDIUMCVSS 2.0
EPSS 6.34%
Description
Multiple PHP remote file inclusion vulnerabilities in Dolphin 5.1 allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter in (1) index.php, (2) aemodule.php, (3) browse.php, (4) cc.php, (5) click.php, (6) faq.php, (7) gallery.php, (8) im.php, (9) inbox.php, (10) join_form.php, (11) logout.php, (12) messages_inbox.php, and many other scripts.
Affected products
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:H/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2022-2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 6.34% (0.06344) | 93.44th | v5 (v2026.06.15) |
| Jul 15, 2026 | 6.23% (0.06228) | 92.73th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.80% (0.03802) | 88.59th | v5 (v2026.06.15) |
| Sep 10, 2025 | 5.68% (0.05676) | 90.03th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.83% (0.02828) | 85.25th | v4 (v2025.03.14) |
| Dec 17, 2024 | 20.81% (0.20808) | 96.39th | v3 (v2023.03.01) |
| Apr 22, 2024 | 51.74% (0.51738) | 97.53th | v3 (v2023.03.01) |
| Feb 27, 2024 | 43.99% (0.43987) | 97.25th | v3 (v2023.03.01) |
| Nov 20, 2023 | 39.36% (0.39359) | 96.89th | v3 (v2023.03.01) |
| Oct 12, 2023 | 43.78% (0.43781) | 96.94th | v3 (v2023.03.01) |
| Sep 4, 2023 | 51.47% (0.51474) | 97.13th | v3 (v2023.03.01) |
| Jul 28, 2023 | 22.14% (0.22140) | 95.84th | v3 (v2023.03.01) |
| Jun 20, 2023 | 9.44% (0.09435) | 93.86th | v3 (v2023.03.01) |
| May 13, 2023 | 6.32% (0.06316) | 92.53th | v3 (v2023.03.01) |
| Apr 5, 2023 | 4.81% (0.04809) | 91.47th | v3 (v2023.03.01) |
| Mar 7, 2023 | 4.78% (0.04780) | 91.41th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.93% (0.03932) | 85.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.93% (0.03932) | 84.43th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.93% (0.03932) | 67.70th | v2 (v2022.01.01) |
No CWE recorded.
References (45)
- http://secunia.com/advisories/21535 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securitytracker.com/id?1016692 vdb-entryx_refsource_SECTRACKExploit
- http://www.osvdb.org/28473 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28474 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28478 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28479 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28485 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28492 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28493 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28496 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28498 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28499 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28500 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28501 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28502 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28503 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28504 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28505 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28506 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28507 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28508 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28509 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28510 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28511 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28512 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28513 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28514 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28515 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28516 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28517 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28519 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28520 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28521 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28522 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28523 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28524 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28525 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28526 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28527 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28528 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28529 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/28530 vdb-entryx_refsource_OSVDBExploit
- http://www.securityfocus.com/bid/21182 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2006/3346 vdb-entryx_refsource_VUPEN
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28363 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/21535 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://securitytracker.com/id?1016692 | vdb-entryx_refsource_SECTRACKExploit | |
| http://www.osvdb.org/28473 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28474 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28478 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28479 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28485 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28492 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28493 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28496 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28498 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28499 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28500 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28501 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28502 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28503 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28504 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28505 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28506 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28507 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28508 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28509 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28510 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28511 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28512 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28513 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28514 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28515 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28516 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28517 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28519 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28520 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28521 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28522 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28523 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28524 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28525 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28526 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28527 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28528 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28529 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.osvdb.org/28530 | vdb-entryx_refsource_OSVDBExploit | |
| http://www.securityfocus.com/bid/21182 | vdb-entryx_refsource_BID | |
| http://www.vupen.com/english/advisories/2006/3346 | vdb-entryx_refsource_VUPEN | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/28363 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.