Back

CVE-2006-0308

PHP remote file inclusion vulnerability in htmltonuke.php in the htmltonuke 2.0 alpha, and possibly other versions, module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the filnavn parameter.

Published: Jan 19, 2006 Modified: Jun 16, 2026
CWE-94

CVSS Metrics

Affected Products (1)

Vendor Product Version
htmltonuke htmltonuke 2.0_alpha

GitHub Security Advisory GHSA-8jwm-2grr-52wm

PHP remote file inclusion vulnerability in htmltonuke.php in the htmltonuke 2.0 alpha, and...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.57%

Top 16% most likely to be exploited

Threat Score 30.8 / 100

Data Sources

NVD EPSS GitHub