CVE-2006-4837
Published · Updated
25Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Attendepss 2.8%
from disclosure to weapon
Published on NVDSep 15
VulnCheck+6996d
exploitation probability
2.8%top 14% of all CVEs
observed exploitation
yesVulnCheck
Multiple PHP remote file inclusion vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) library/lib.php and (2) library/editor/editor.php. NOTE: the same primary issue can be used for full path disclosure with an invalid parameter that reveals the installation path in an error message.
Affected products
n/a · n/a