Unrated severityNVD Advisory· Published Oct 31, 2006· Updated Jun 16, 2026
CVE-2006-5627
CVE-2006-5627
Description
Multiple PHP remote file inclusion vulnerabilities in QnECMS 2.5.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the adminfolderpath parameter to (1) headerscripts.php, (2) footerhome.php, and (3) footermain.php in admin/include/; (4) photogallery/headerscripts.php; and (5) footerhome.php, (6) footermain.php, (7) headermain.php, (8) sitemapfooter.php, and (9) sitemapheader.php in templates/.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
17- secunia.com/advisories/22623nvdVendor Advisory
- advisories.echo.or.id/adv/adv53-K-159-2006.txtnvd
- www.osvdb.org/30117nvd
- www.osvdb.org/30118nvd
- www.osvdb.org/30119nvd
- www.osvdb.org/30120nvd
- www.osvdb.org/30121nvd
- www.osvdb.org/30122nvd
- www.osvdb.org/30123nvd
- www.osvdb.org/30124nvd
- www.osvdb.org/30125nvd
- www.securityfocus.com/archive/1/450056/100/0/threadednvd
- www.securityfocus.com/archive/1/452356/100/0/threadednvd
- www.securityfocus.com/bid/20801nvd
- www.vupen.com/english/advisories/2006/4258nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/29871nvd
- www.exploit-db.com/exploits/2681nvd
News mentions
0No linked articles in our index yet.