Back

CVE-2006-0945

PHP remote file include vulnerability in admin/index.php in Archangel Weblog 0.90.02 allows remote authenticated administrators to execute arbitrary PHP code via a URL ending in a NULL (%00) in the index parameter.

Published: Mar 1, 2006 Modified: Jun 16, 2026
CWE-94

CVSS Metrics

Affected Products (1)

Vendor Product Version
archangelmgt weblog 0.90.02

GitHub Security Advisory GHSA-h4fq-c9g5-9qmg

PHP remote file include vulnerability in admin/index.php in Archangel Weblog 0.90.02 allows...

Risk Scores

CVSS Score 6.5 / 10
EPSS Score 1.31%

Top 32% most likely to be exploited

Threat Score 26.4 / 100

Data Sources

NVD EPSS GitHub