CVE-2006-4848
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 6.3%
from disclosure to weapon0 days
Published on NVDSep 19
1st PoCSep 16
exploitation probability
6.3%top 7% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Multiple PHP remote file inclusion vulnerabilities in Brian Fraval Hitweb 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the REP_CLASS parameter to (1) index.php, (2) arbo.php, (3) framepoint.php, (4) genpage.php, (5) lienvalider.php, (6) appreciation.php, (7) partenariat.php, (8) rechercher.php, (9) projet.php, (10) propoexample.php, (11) refererpoint.php, or (12) top50.php. NOTE: this issue has been disputed by a third party researcher, stating that REP_CLASS is initialized in an included file before being used
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/28590⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.