CVE-2006-0478
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 3.1%
from disclosure to weapon0 days
Published on NVDJan 31
1st PoCJan 24
exploitation probability
3.1%top 14% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
CRE Loaded 6.15 allows remote attackers to perform privileged actions, including uploading and creating arbitrary files, via a direct request to files.php. NOTE: the vendor states "The initial announcement of this risk was made on our website... and it included a patch which will close the vulnerability on all known 6.0x and 6.1x releases. We strongly encourage users of CRE Loaded 6.x, osCMax, and other users of osCommerce who have installed HTMLArea based WYSIWYG editors and Admin Access with Levels to modify thier installations at the earliest possible moment."
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/1446⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.