Unrated severityNVD Advisory· Published Sep 13, 2006· Updated Apr 16, 2026
CVE-2006-4750
CVE-2006-4750
Description
PHP remote file inclusion vulnerability in openi-admin/base/fileloader.php in OPENi-CMS 1.0.1, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the config[openi_dir] parameter.
Affected products
2cpe:2.3:a:openi-cms_group:openi-cms:1.0.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:openi-cms_group:openi-cms:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:openi-cms_group:openi-cms:1.0.1_beta1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- bb.domaindlx.com/bingung/shellcore/advisories.aspnvdExploitVendor Advisory
- secunia.com/advisories/21874nvdExploitVendor Advisory
- www.securityfocus.com/bid/19952nvdExploit
- www.vupen.com/english/advisories/2006/3556nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/28859nvd
- www.exploit-db.com/exploits/2344nvd
News mentions
0No linked articles in our index yet.