Unrated severityNVD Advisory· Published Nov 8, 2006· Updated Apr 23, 2026
CVE-2006-5796
CVE-2006-5796
Description
Multiple PHP remote file inclusion vulnerabilities in Soholaunch Pro Edition 4.9 r46 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the _SESSION[docroot_path] parameter to (1) includes/shared_functions.php or (2) client_files/shopping_cart/pgm-shopping_css.inc.php.
Affected products
1- cpe:2.3:a:soholaunch:soholaunch_pro_edition:4.9_r36:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- advisories.echo.or.id/adv/adv57-theday-2006.txtnvdExploitVendor Advisory
- marc.infonvd
- secunia.com/advisories/22735nvd
- www.osvdb.org/30238nvd
- www.osvdb.org/displayvuln.phpnvd
- www.vupen.com/english/advisories/2006/4377nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/30032nvd
- www.exploit-db.com/exploits/2724nvd
News mentions
0No linked articles in our index yet.