Back
CVE-2006-0945
PHP remote file include vulnerability in admin/index.php in Archangel Weblog 0.90.02 allows remote authenticated administrators to execute arbitrary PHP code via a URL ending in a NULL (%00) in the index parameter.
Published: Mar 1, 2006
Modified: Jun 16, 2026
CWE-94
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| archangelmgt | weblog | 0.90.02 |
GitHub Security Advisory GHSA-h4fq-c9g5-9qmg
PHP remote file include vulnerability in admin/index.php in Archangel Weblog 0.90.02 allows...
References (10)
- http://securitytracker.com/id?1015689
- http://www.osvdb.org/23621
- http://www.securityfocus.com/archive/1/426184/100/0/threaded
- http://www.securityfocus.com/bid/16848
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25142
- http://securitytracker.com/id?1015689
- http://www.osvdb.org/23621
- http://www.securityfocus.com/archive/1/426184/100/0/threaded
- http://www.securityfocus.com/bid/16848
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25142
Risk Scores
CVSS Score
6.5 / 10
EPSS Score
1.31%
Top 32% most likely to be exploited
Threat Score
26.4 / 100
Data Sources
NVD
EPSS
GitHub