Multiple PHP remote file inclusion vulnerabilities in OpenDock FullCore 4.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) sw/index_sw.php; (2) cart.php, (3) lib_cart.php, (4) lib_read_cart.php, (5) lib_sys_cart.php, and (6) txt_info_cart.php in sw/lib_cart/; (7) comment.php, (8) find_comment.php, and (9) lib_comment.php in sw/lib_comment/; (10) sw/lib_find/find.php; and other unspecified PHP scripts
Published Oct 18, 2006
7.5
HIGHCVSS 2.0
EPSS 16.46%
Description
Multiple PHP remote file inclusion vulnerabilities in OpenDock FullCore 4.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) sw/index_sw.php; (2) cart.php, (3) lib_cart.php, (4) lib_read_cart.php, (5) lib_sys_cart.php, and (6) txt_info_cart.php in sw/lib_cart/; (7) comment.php, (8) find_comment.php, and (9) lib_comment.php in sw/lib_comment/; (10) sw/lib_find/find.php; and other unspecified PHP scripts.
Affected products
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (24 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 16.46% (0.16455) | 96.90th | v5 (v2026.06.15) |
| Sep 15, 2026 | 16.03% (0.16031) | 96.73th | v5 (v2026.06.15) |
| Jun 15, 2026 | 9.68% (0.09675) | 94.87th | v5 (v2026.06.15) |
| Apr 27, 2026 | 28.73% (0.28725) | 96.56th | v4 (v2025.03.14) |
| Apr 25, 2026 | 23.28% (0.23280) | 95.97th | v4 (v2025.03.14) |
| Feb 28, 2026 | 16.97% (0.16968) | 94.84th | v4 (v2025.03.14) |
| Aug 6, 2025 | 14.60% (0.14599) | 94.18th | v4 (v2025.03.14) |
| Jun 6, 2025 | 10.04% (0.10038) | 92.64th | v4 (v2025.03.14) |
| Mar 30, 2025 | 7.94% (0.07938) | 91.25th | v4 (v2025.03.14) |
| Mar 29, 2025 | 12.81% (0.12807) | 90.02th | v4 (v2025.03.14) |
| Mar 17, 2025 | 7.94% (0.07938) | 91.44th | v4 (v2025.03.14) |
| Feb 6, 2025 | 19.70% (0.19702) | 96.36th | v3 (v2023.03.01) |
| Dec 17, 2024 | 17.12% (0.17119) | 96.05th | v3 (v2023.03.01) |
| Sep 7, 2024 | 44.72% (0.44721) | 97.46th | v3 (v2023.03.01) |
| Jun 23, 2024 | 31.94% (0.31937) | 97.04th | v3 (v2023.03.01) |
| Apr 29, 2024 | 26.69% (0.26691) | 96.70th | v3 (v2023.03.01) |
| Mar 12, 2024 | 23.30% (0.23304) | 96.43th | v3 (v2023.03.01) |
| Aug 22, 2023 | 23.93% (0.23933) | 95.98th | v3 (v2023.03.01) |
| Jul 15, 2023 | 15.53% (0.15531) | 95.17th | v3 (v2023.03.01) |
| Jun 7, 2023 | 15.97% (0.15968) | 95.13th | v3 (v2023.03.01) |
| Mar 7, 2023 | 16.27% (0.16265) | 95.08th | v3 (v2023.03.01) |
| Mar 6, 2023 | 12.57% (0.12567) | 95.52th | v2 (v2022.01.01) |
| Apr 1, 2022 | 12.57% (0.12567) | 95.18th | v2 (v2022.01.01) |
| Feb 4, 2022 | 12.57% (0.12567) | 90.03th | v2 (v2022.01.01) |
No CWE recorded.
References (15)
- http://secunia.com/advisories/22410 third-party-advisoryx_refsource_SECUNIA
- http://www.osvdb.org/29906 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/29907 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/29908 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/29909 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/29910 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/29911 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/29912 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/29913 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/29914 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/29915 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/20573 vdb-entryx_refsource_BIDExploit
- http://www.vupen.com/english/advisories/2006/4052 vdb-entryx_refsource_VUPEN
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29578 vdb-entryx_refsource_XF
- https://www.exploit-db.com/exploits/2570 exploitx_refsource_EXPLOIT-DB
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/22410 | third-party-advisoryx_refsource_SECUNIA | |
| http://www.osvdb.org/29906 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/29907 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/29908 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/29909 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/29910 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/29911 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/29912 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/29913 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/29914 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/29915 | vdb-entryx_refsource_OSVDB | |
| http://www.securityfocus.com/bid/20573 | vdb-entryx_refsource_BIDExploit | |
| http://www.vupen.com/english/advisories/2006/4052 | vdb-entryx_refsource_VUPEN | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/29578 | vdb-entryx_refsource_XF | |
| https://www.exploit-db.com/exploits/2570 | exploitx_refsource_EXPLOIT-DB |
Change history (0)
No recorded changes yet.