Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute arbitrary PHP code via a URL in the g_documentRoot parameter to (1) Alias.php, (2) Article.php, (3) ArticleAttachment.php, (4) ArticleComment.php, (5) ArticleData.php, (6) ArticleImage.php, (7) ArticleIndex.php, (8) ArticlePublish.php, (9) ArticleTopic.php, (10) ArticleType.php, (11) ArticleTypeField.php, (12) Attachment.php, (13) Country.php, (14) DatabaseObject.php, (15) Event.php, (16) IPAccess.php, (17) Image.php, (18) Issue.php, (19) IssuePublish.php, (20) Language.php, (21) Log.php, (22) LoginAttempts.php, (23) Publication.php, (24) Section.php, (25) ShortURL.php, (26) Subscription.php, (27) SubscriptionDefaultTime.php, (28) SubscriptionSection.php, (29) SystemPref.php, (30) Template.php, (31) TimeUnit.php, (32) Topic.php, (33) UrlType.php, (34) User.php, and (35) UserType.php in implementation/management/classes/; (36) configuration.php and (37) db_connect.php in implementation/management/; and (38) LocalizerConfig.php and (39) LocalizerLanguage.php in implementation/management/priv/localizer/
Published Nov 15, 2006
7.5
HIGHCVSS 2.0
EPSS 4.56%
Description
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute arbitrary PHP code via a URL in the g_documentRoot parameter to (1) Alias.php, (2) Article.php, (3) ArticleAttachment.php, (4) ArticleComment.php, (5) ArticleData.php, (6) ArticleImage.php, (7) ArticleIndex.php, (8) ArticlePublish.php, (9) ArticleTopic.php, (10) ArticleType.php, (11) ArticleTypeField.php, (12) Attachment.php, (13) Country.php, (14) DatabaseObject.php, (15) Event.php, (16) IPAccess.php, (17) Image.php, (18) Issue.php, (19) IssuePublish.php, (20) Language.php, (21) Log.php, (22) LoginAttempts.php, (23) Publication.php, (24) Section.php, (25) ShortURL.php, (26) Subscription.php, (27) SubscriptionDefaultTime.php, (28) SubscriptionSection.php, (29) SystemPref.php, (30) Template.php, (31) TimeUnit.php, (32) Topic.php, (33) UrlType.php, (34) User.php, and (35) UserType.php in implementation/management/classes/; (36) configuration.php and (37) db_connect.php in implementation/management/; and (38) LocalizerConfig.php and (39) LocalizerLanguage.php in implementation/management/priv/localizer/.
Affected products
No data.
- 2.6.0
- 2.6.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 4.56% (0.04557) | 91.32th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.44% (0.04441) | 90.13th | v5 (v2026.06.15) |
| Mar 17, 2025 | 3.38% (0.03384) | 86.55th | v4 (v2025.03.14) |
| Dec 12, 2024 | 19.09% (0.19092) | 96.45th | v3 (v2023.03.01) |
| Oct 5, 2024 | 19.09% (0.19092) | 96.35th | v3 (v2023.03.01) |
| Jul 21, 2024 | 16.52% (0.16517) | 96.08th | v3 (v2023.03.01) |
| May 27, 2024 | 17.57% (0.17573) | 96.13th | v3 (v2023.03.01) |
| Apr 9, 2024 | 11.25% (0.11248) | 95.09th | v3 (v2023.03.01) |
| Sep 19, 2023 | 15.52% (0.15520) | 95.23th | v3 (v2023.03.01) |
| Aug 12, 2023 | 6.55% (0.06549) | 92.81th | v3 (v2023.03.01) |
| Apr 19, 2023 | 6.76% (0.06758) | 92.80th | v3 (v2023.03.01) |
| Mar 7, 2023 | 6.57% (0.06572) | 92.61th | v3 (v2023.03.01) |
| Mar 6, 2023 | 15.27% (0.15272) | 95.95th | v2 (v2022.01.01) |
| Apr 1, 2022 | 15.27% (0.15272) | 95.58th | v2 (v2022.01.01) |
| Feb 4, 2022 | 15.27% (0.15272) | 91.38th | v2 (v2022.01.01) |
No CWE recorded.
References (45)
- http://code.campware.org/projects/campsite/changeset/6057 x_refsource_CONFIRMPatch
- http://code.campware.org/projects/campsite/changeset/6058 x_refsource_CONFIRMPatch
- http://code.campware.org/projects/campsite/query?milestone=2.6.2 x_refsource_CONFIRM
- http://code.campware.org/projects/campsite/ticket/2349 x_refsource_CONFIRM
- http://sourceforge.net/project/shownotes.php?release_id=459574&group_id=66936 x_refsource_CONFIRMPatch
- http://www.osvdb.org/34187 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34188 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34189 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34190 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34191 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34192 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34193 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34194 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34195 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34196 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34197 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34198 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34199 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34200 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34201 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34202 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34203 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34204 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34205 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34206 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34207 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34208 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34209 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34210 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34211 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34212 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34213 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34214 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34215 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34216 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34217 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34218 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34219 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34220 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34221 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34222 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34223 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34224 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34225 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/23874 vdb-entryx_refsource_BID
Change history (0)
No recorded changes yet.