CVE-2006-2666
published 2006-05-30CVE-2006-2666: PHP remote file inclusion vulnerability in includes/mailaccess/pop3.php in V-Webmail 1.5 through 1.6.4 allows remote attackers to execute arbitrary PHP code…
PriorityP343high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
3.56%
87.9th percentile
PHP remote file inclusion vulnerability in includes/mailaccess/pop3.php in V-Webmail 1.5 through 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[pear_dir] parameter.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| christof_bruyland | v-webmail | — | — |
| v-webmail | v-webmail | <= 1.6.4 | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fwr4-xgj3-34f3: Multiple PHP remote file inclusion vulnerabilities in V-webmail 1
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2008-6840 [HIGH] CWE-94 GHSA-fwr4-xgj3-34f3: Multiple PHP remote file inclusion vulnerabilities in V-webmail 1
Multiple PHP remote file inclusion vulnerabilities in V-webmail 1.6.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG[pear_dir] parameter to (a) Mail/RFC822.php, (b) Net/Socket.php, (c) XML/Parser.php, (d) XML/Tree.php, (e) Mail/mimeDecode.php, (f) Console/Getopt.php, (g) System.php, (h) Log.php, and (i) File.php in includes/pear/; the CONFIG[pear_dir] parameter to (j) includes/prepend.php, and (k) includes/cachedConfig.php; and the (2) CONFIG[includes] parameter to (l) prepend.php and (m) email.list.search.php in includes/. NOTE: the CONFIG[pear_dir] parameter to includes/mailaccess/pop3.php is already covered by CVE-2006-2666.
GHSA
GHSA-4jq5-g3h6-g64m: PHP remote file inclusion vulnerability in includes/mailaccess/pop3
ghsa_unreviewed·2022-05-01
CVE-2006-2666 [HIGH] GHSA-4jq5-g3h6-g64m: PHP remote file inclusion vulnerability in includes/mailaccess/pop3
PHP remote file inclusion vulnerability in includes/mailaccess/pop3.php in V-Webmail 1.5 through 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[pear_dir] parameter.
No detection rules found.
No writeups or analysis indexed.
http://secunia.com/advisories/20297http://securitytracker.com/id?1016160http://www.securityfocus.com/bid/30164http://www.vupen.com/english/advisories/2006/1989https://exchange.xforce.ibmcloud.com/vulnerabilities/26694https://www.exploit-db.com/exploits/1827http://secunia.com/advisories/20297http://securitytracker.com/id?1016160http://www.securityfocus.com/bid/30164http://www.vupen.com/english/advisories/2006/1989https://exchange.xforce.ibmcloud.com/vulnerabilities/26694https://www.exploit-db.com/exploits/1827
2006-05-30
Published