Unrated severityNVD Advisory· Published May 24, 2006· Updated Apr 16, 2026
CVE-2006-2578
CVE-2006-2578
Description
admin/cron.php in eSyndicat Directory 1.2, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include arbitrary files and possibly execute arbitrary PHP code via a null-terminated value in the path_to_config parameter.
Affected products
1- cpe:2.3:a:esyndicat:esyndicat_directory:1.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.