← back
CVE-2006-0147

CVE-2006-0147

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 13%
exploitation probability
13%top 4% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to execute arbitrary PHP functions via the do parameter, which is saved in a variable that is then executed as a function, as demonstrated using phpinfo.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.