Back

CVE-2006-0075

Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via the e-mail field (mail variable) in a new message, which is written to a PHP file.

Published: Jan 4, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (5)

Vendor Product Version
gnu phpbook *
gnu phpbook 1.0
gnu phpbook 1.1
gnu phpbook 1.2
gnu phpbook 1.3

GitHub Security Advisory GHSA-x7qp-69q5-6r8h

Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.74%

Top 15% most likely to be exploited

Threat Score 30.8 / 100

Data Sources

NVD EPSS GitHub