Multiple PHP remote file inclusion vulnerabilities in PhotoPost allow remote attackers to execute arbitrary PHP code via a URL in the PP_PATH parameter in (1) addfav.php, (2) adm-admlog.php, (3) adm-approve.php, (4) adm-backup.php, (5) adm-cats.php, (6) adm-cinc.php, (7) adm-db.php, (8) adm-editcfg.php, (9) adm-inc.php, (10) adm-index.php, (11) adm-modcom.php, (12) adm-move.php, (13) adm-options.php, (14) adm-order.php, (15) adm-pa.php, (16) adm-photo.php, (17) adm-purge.php, (18) adm-style.php, (19) adm-templ.php, (20) adm-userg.php, (21) adm-users.php, (22) bulkupload.php, (23) cookies.php, (24) comments.php, (25) ecard.php, (26) editphoto.php, (27) register.php, (28) showgallery.php, (29) showmembers.php, (30) useralbums.php, (31) uploadphoto.php, (32) search.php, or (33) adm-menu.php, different vectors than CVE-2006-4828
Published Sep 26, 2006
7.5
HIGHCVSS 2.0
EPSS 4.20%
Description
Multiple PHP remote file inclusion vulnerabilities in PhotoPost allow remote attackers to execute arbitrary PHP code via a URL in the PP_PATH parameter in (1) addfav.php, (2) adm-admlog.php, (3) adm-approve.php, (4) adm-backup.php, (5) adm-cats.php, (6) adm-cinc.php, (7) adm-db.php, (8) adm-editcfg.php, (9) adm-inc.php, (10) adm-index.php, (11) adm-modcom.php, (12) adm-move.php, (13) adm-options.php, (14) adm-order.php, (15) adm-pa.php, (16) adm-photo.php, (17) adm-purge.php, (18) adm-style.php, (19) adm-templ.php, (20) adm-userg.php, (21) adm-users.php, (22) bulkupload.php, (23) cookies.php, (24) comments.php, (25) ecard.php, (26) editphoto.php, (27) register.php, (28) showgallery.php, (29) showmembers.php, (30) useralbums.php, (31) uploadphoto.php, (32) search.php, or (33) adm-menu.php, different vectors than CVE-2006-4828.
Affected products
No data.
- 4.5
- 4.6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (17 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 4.20% (0.04200) | 90.65th | v5 (v2026.06.15) |
| Aug 24, 2026 | 4.20% (0.04200) | 90.18th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.49% (0.02491) | 82.52th | v5 (v2026.06.15) |
| Mar 30, 2025 | 2.77% (0.02765) | 84.75th | v4 (v2025.03.14) |
| Mar 29, 2025 | 3.79% (0.03791) | 79.90th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.77% (0.02765) | 85.07th | v4 (v2025.03.14) |
| Dec 12, 2024 | 13.31% (0.13315) | 95.79th | v3 (v2023.03.01) |
| Nov 21, 2023 | 13.31% (0.13315) | 95.01th | v3 (v2023.03.01) |
| Oct 14, 2023 | 41.67% (0.41674) | 96.87th | v3 (v2023.03.01) |
| Sep 6, 2023 | 11.07% (0.11066) | 94.42th | v3 (v2023.03.01) |
| Jul 30, 2023 | 3.37% (0.03372) | 90.10th | v3 (v2023.03.01) |
| Jun 22, 2023 | 2.62% (0.02616) | 88.82th | v3 (v2023.03.01) |
| May 15, 2023 | 2.85% (0.02855) | 89.21th | v3 (v2023.03.01) |
| Mar 7, 2023 | 2.76% (0.02756) | 88.93th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.36% (0.04358) | 88.02th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.36% (0.04358) | 86.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.36% (0.04358) | 70.59th | v2 (v2022.01.01) |
No CWE recorded.
References (32)
- http://securityreason.com/securityalert/1632 third-party-advisoryx_refsource_SREASON
- http://www.osvdb.org/32221 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32222 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32223 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32224 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32225 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32226 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32227 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32228 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32229 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32230 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32231 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32232 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32233 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32234 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32235 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32236 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32237 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32238 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32239 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32240 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32243 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32245 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32246 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32247 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32248 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32249 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32250 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32251 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32252 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/32253 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/archive/1/446224/100/0/threaded mailing-listx_refsource_BUGTRAQ
| Link | Providers | Tags |
|---|---|---|
| http://securityreason.com/securityalert/1632 | third-party-advisoryx_refsource_SREASON | |
| http://www.osvdb.org/32221 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32222 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32223 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32224 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32225 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32226 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32227 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32228 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32229 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32230 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32231 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32232 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32233 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32234 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32235 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32236 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32237 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32238 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32239 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32240 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32243 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32245 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32246 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32247 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32248 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32249 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32250 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32251 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32252 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/32253 | vdb-entryx_refsource_OSVDB | |
| http://www.securityfocus.com/archive/1/446224/100/0/threaded | mailing-listx_refsource_BUGTRAQ |
Change history (0)
No recorded changes yet.