CVE-2006-1371
HIGH 9.0EPSS 9.4%
Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5 and earlier allows remote authenticated users to use the HTMLArea FileManager plugin to upload and execute arbitrary PHP files using (1) manager.php, (2) standalonemanager.php, and (3) images.php.
- CVSS v2.0
- 9.0 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C - EPSS
- 9.40% chance of exploitation in the next 30 days, 95th percentile
- Published
- 2006-03-23
- Updated
- 2024-08-07