VYPR
Unrated severityNVD Advisory· Published Dec 4, 2006· Updated Apr 23, 2026

CVE-2006-6255

CVE-2006-6255

Description

Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an AIML chatterbot, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension in the filename parameter and code in the moreinfo parameter, which is saved to a filename under descriptions/, which is accessible via a direct request.

Affected products

1
  • cpe:2.3:a:nukeai:nukeai:0.0.3_beta:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.