CVE-2006-5124
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 3.5%
from disclosure to weapon0 days
Published on NVDOct 2
1st PoCSep 30
exploitation probability
3.5%top 12% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) target and (2) action parameters in window.php, and possibly the (3) target parameter in home.php.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/2462unverifiedcve_referencewww.exploit-db.com/exploits/2451unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://kernel-32.blogspot.com/2006/09/php-mywebmin-10-remote-file-include.htmlhttp://secunia.com/advisories/22178https://exchange.xforce.ibmcloud.com/vulnerabilities/29258https://www.exploit-db.com/exploits/2451http://www.securityfocus.com/bid/20264http://www.vupen.com/english/advisories/2006/3846