Loading...
Loading...
Multiple direct static code injection vulnerabilities in db/txt.inc.php in phpPowerCards 2.10, when register_globals is enabled, allow remote attackers to create or overwrite arbitrary files via the (1) email[to], (2) email[from], (3) name[to], (4) name[from], (5) picture, (6) comment, or (7) sessionID parameter, as demonstrated by creating a new .php file that permits remote file inclusion, and then requesting this file.
October 20, 2006
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2006-5432
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.