PHP remote file inclusion vulnerability in order/index.php in IDevSpot (1) PhpHostBot 1.0 and (2) AutoHost 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
Loading...
Loading...
PHP remote file inclusion vulnerability in order/index.php in IDevSpot (1) PhpHostBot 1.0 and (2) AutoHost 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
July 24, 2006
April 16, 2026
Working exploit code is in the public domain (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
IDevSpot PHPHostBot 1.0 - 'index.php' Remote File Inclusion
Open source ↗See which npm, PyPI, Go, and Maven packages are affected by CVE-2006-3776
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.