Multiple PHP remote file inclusion vulnerabilities in Plume CMS 1.0.6 and earlier allow remote attackers to execute arbitrary PHP code via the _PX_config[manager_path] parameter to (1) articles.php, (2) categories.php, (3) news.php, (4) prefs.php, (5) sites.php, (6) subtypes.php, (7) users.php, (8) xmedia.php, (9) frontinc/class.template.php, (10) inc/lib.text.php, (11) install/index.php, (12) install/upgrade.php, and (13) tools/htaccess/index.php
Published Sep 1, 2006
7.5
HIGHCVSS 2.0
EPSS 4.33%
Description
Multiple PHP remote file inclusion vulnerabilities in Plume CMS 1.0.6 and earlier allow remote attackers to execute arbitrary PHP code via the _PX_config[manager_path] parameter to (1) articles.php, (2) categories.php, (3) news.php, (4) prefs.php, (5) sites.php, (6) subtypes.php, (7) users.php, (8) xmedia.php, (9) frontinc/class.template.php, (10) inc/lib.text.php, (11) install/index.php, (12) install/upgrade.php, and (13) tools/htaccess/index.php. NOTE: other vectors are covered by CVE-2006-3562, CVE-2006-2645, and CVE-2006-0725.
Affected products
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (17 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.33% (0.04332) | 90.89th | v5 (v2026.06.15) |
| Jul 30, 2026 | 4.25% (0.04252) | 90.05th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.59% (0.02589) | 83.20th | v5 (v2026.06.15) |
| Mar 17, 2025 | 2.37% (0.02367) | 83.85th | v4 (v2025.03.14) |
| Dec 12, 2024 | 25.76% (0.25758) | 96.89th | v3 (v2023.03.01) |
| Jan 25, 2024 | 25.76% (0.25758) | 96.28th | v3 (v2023.03.01) |
| Dec 6, 2023 | 19.95% (0.19946) | 95.83th | v3 (v2023.03.01) |
| Oct 28, 2023 | 15.33% (0.15333) | 95.25th | v3 (v2023.03.01) |
| Sep 20, 2023 | 45.46% (0.45457) | 96.94th | v3 (v2023.03.01) |
| Aug 13, 2023 | 11.08% (0.11076) | 94.39th | v3 (v2023.03.01) |
| Jul 6, 2023 | 3.37% (0.03366) | 90.04th | v3 (v2023.03.01) |
| May 29, 2023 | 2.41% (0.02407) | 88.34th | v3 (v2023.03.01) |
| Apr 21, 2023 | 2.63% (0.02628) | 88.75th | v3 (v2023.03.01) |
| Mar 7, 2023 | 3.55% (0.03551) | 90.14th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.78% (0.03779) | 85.48th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.78% (0.03779) | 84.01th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.78% (0.03779) | 67.21th | v2 (v2022.01.01) |
References (15)
- http://packetstormsecurity.org/0608-exploits/plume-1.0.6.txt x_refsource_MISC
- http://www.osvdb.org/31171 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/31172 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/31173 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/31174 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/31175 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/31176 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/31177 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/31178 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/31179 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/31180 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/31181 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/31182 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/31183 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/19629 vdb-entryx_refsource_BID
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.org/0608-exploits/plume-1.0.6.txt | x_refsource_MISC | |
| http://www.osvdb.org/31171 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/31172 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/31173 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/31174 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/31175 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/31176 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/31177 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/31178 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/31179 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/31180 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/31181 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/31182 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/31183 | vdb-entryx_refsource_OSVDB | |
| http://www.securityfocus.com/bid/19629 | vdb-entryx_refsource_BID |
Change history (0)
No recorded changes yet.