← Back to browse · API

CVE-2006-4428

Severity
CRITICAL
CVSS
9.8
EPSS
0.04338
Risk score
40.72
CISA KEV
No
PoC
No
Published
2006-08-29
Modified
2025-01-17
First seen
2026-08-07
Aliases
EUVD-2006-4416, GHSA-M8PG-MX2H-FQ4V
Products
n/a:n/a n/a
Sources
euvd EUVD-2006-4416

Description

PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to execute arbitrary PHP code via a URL in the template parameter. NOTE: CVE disputes this claim, since the $template variable is defined as a static value before it is referenced in an include statement

References