Back
CVE-2006-0075
Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via the e-mail field (mail variable) in a new message, which is written to a PHP file.
Published: Jan 4, 2006
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (5)
| Vendor | Product | Version |
|---|---|---|
| gnu | phpbook | * |
| gnu | phpbook | 1.0 |
| gnu | phpbook | 1.1 |
| gnu | phpbook | 1.2 |
| gnu | phpbook | 1.3 |
GitHub Security Advisory GHSA-x7qp-69q5-6r8h
Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers...
References (10)
- http://evuln.com/vulns/6/summary.html Patch
- http://secunia.com/advisories/18268 Vendor Advisory
- http://www.securityfocus.com/archive/1/420698/100/0/threaded
- http://www.securityfocus.com/bid/16106 Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0002
- http://evuln.com/vulns/6/summary.html Patch
- http://secunia.com/advisories/18268 Vendor Advisory
- http://www.securityfocus.com/archive/1/420698/100/0/threaded
- http://www.securityfocus.com/bid/16106 Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0002
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
2.74%
Top 15% most likely to be exploited
Threat Score
30.8 / 100
Data Sources
NVD
EPSS
GitHub