Unrated severityNVD Advisory· Published Jan 29, 2007· Updated Apr 23, 2026
CVE-2006-6958
CVE-2006-6958
Description
Multiple PHP remote file inclusion vulnerabilities in phpBlueDragon 2.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the vsDragonRootPath parameter to (1) team_admin.php, (2) rss_admin.php, (3) manual_admin.php, and (4) forum_admin.php in includes/root_modules/, a different set of vectors than CVE-2006-3076.
Affected products
1- cpe:2.3:a:phpbluedragon:phpbluedragon_cms:2.9.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- packetstormsecurity.org/0606-exploits/phpbluedragon-2.txtnvdExploit
- www.securityfocus.com/bid/18609nvdExploit
- securityreason.com/securityalert/2193nvd
- www.osvdb.org/27676nvd
- www.osvdb.org/27677nvd
- www.osvdb.org/27678nvd
- www.osvdb.org/27679nvd
- www.securityfocus.com/archive/1/438238/100/100/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/27152nvd
News mentions
0No linked articles in our index yet.