{"api_version":"1","generated_at":"2026-07-23T10:23:51+00:00","cve":"CVE-2006-0169","urls":{"html":"https://cve.report/CVE-2006-0169","api":"https://cve.report/api/cve/CVE-2006-0169.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-0169","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-0169"},"summary":{"title":"CVE-2006-0169","description":"addresses.php3 in MyPhPim 01.05 does not restrict uploaded files, which allows remote attackers to execute arbitrary PHP code via the pdbfile variable, then directly accessing those files from the uploads directory.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-01-11 21:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://evuln.com/vulns/23/summary.html","name":"http://evuln.com/vulns/23/summary.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"eVuln.com - MyPhPim Arbitrary File Upload","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/16208","name":"http://www.securityfocus.com/bid/16208","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"MyPhPim Addresses.PHP3 Arbitrary File Upload Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24070","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24070","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/421626/100/0/threaded","name":"http://www.securityfocus.com/archive/1/421626/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/0147","name":"http://www.vupen.com/english/advisories/2006/0147","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/18399","name":"http://secunia.com/advisories/18399","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"MyPHPim Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-0169","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-0169","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"169","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"myphpim","cpe5":"myphpim","cpe6":"01.05","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:25:33.950Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://evuln.com/vulns/23/summary.html"},{"name":"16208","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/16208"},{"name":"18399","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18399"},{"name":"20060111 [eVuln] MyPhPim Arbitrary File Upload","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/421626/100/0/threaded"},{"name":"myphpim-addresses-file-upload(24070)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24070"},{"name":"ADV-2006-0147","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/0147"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-01-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"addresses.php3 in MyPhPim 01.05 does not restrict uploaded files, which allows remote attackers to execute arbitrary PHP code via the pdbfile variable, then directly accessing those files from the uploads directory."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-19T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://evuln.com/vulns/23/summary.html"},{"name":"16208","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/16208"},{"name":"18399","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18399"},{"name":"20060111 [eVuln] MyPhPim Arbitrary File Upload","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/421626/100/0/threaded"},{"name":"myphpim-addresses-file-upload(24070)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24070"},{"name":"ADV-2006-0147","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/0147"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-0169","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"addresses.php3 in MyPhPim 01.05 does not restrict uploaded files, which allows remote attackers to execute arbitrary PHP code via the pdbfile variable, then directly accessing those files from the uploads directory."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://evuln.com/vulns/23/summary.html","refsource":"MISC","url":"http://evuln.com/vulns/23/summary.html"},{"name":"16208","refsource":"BID","url":"http://www.securityfocus.com/bid/16208"},{"name":"18399","refsource":"SECUNIA","url":"http://secunia.com/advisories/18399"},{"name":"20060111 [eVuln] MyPhPim Arbitrary File Upload","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/421626/100/0/threaded"},{"name":"myphpim-addresses-file-upload(24070)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24070"},{"name":"ADV-2006-0147","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/0147"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-0169","datePublished":"2006-01-11T21:00:00.000Z","dateReserved":"2006-01-11T00:00:00.000Z","dateUpdated":"2024-08-07T16:25:33.950Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-01-11 21:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:myphpim:myphpim:01.05:*:*:*:*:*:*:*","matchCriteriaId":"4FC3902D-1B2F-4665-A715-8A0A0803F5B5"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"169","Ordinal":"1","Title":"CVE-2006-0169","CVE":"CVE-2006-0169","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"169","Ordinal":"1","NoteData":"addresses.php3 in MyPhPim 01.05 does not restrict uploaded files, which allows remote attackers to execute arbitrary PHP code via the pdbfile variable, then directly accessing those files from the uploads directory.","Type":"Description","Title":"CVE-2006-0169"},{"CveYear":"2006","CveId":"169","Ordinal":"2","NoteData":"2006-01-11","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"169","Ordinal":"3","NoteData":"2018-10-19","Type":"Other","Title":"Modified"}]}}}