{"api_version":"1","generated_at":"2026-07-23T02:15:17+00:00","cve":"CVE-2006-2005","urls":{"html":"https://cve.report/CVE-2006-2005","api":"https://cve.report/api/cve/CVE-2006-2005.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-2005","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-2005"},"summary":{"title":"CVE-2006-2005","description":"Eval injection vulnerability in index.php in ClanSys 1.1 allows remote attackers to execute arbitrary PHP code via PHP code in the page parameter, as demonstrated by using an \"include\" statement that is injected into the eval statement.  NOTE: this issue has been described as file inclusion by some sources, but that is just one attack; the primary vulnerability is eval injection.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-04-25 12:50:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://securitytracker.com/id?1015988","name":"http://securitytracker.com/id?1015988","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Clansys Input Validation Bug in 'page' Parameter Lets Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25976","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25976","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/782","name":"http://securityreason.com/securityalert/782","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityReason - Clansys <= 1.1 PHP Code Insertion Vulnerability.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/431873/100/0/threaded","name":"http://www.securityfocus.com/archive/1/431873/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/25083","name":"http://www.osvdb.org/25083","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.nukedx.com/?getxpl=29","name":"http://www.nukedx.com/?getxpl=29","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"ClanSys v1.1 (index.php page) PHP Code Insertion Vulnerability","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/17660","name":"http://www.securityfocus.com/bid/17660","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Clansys Index.PHP Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-2005","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-2005","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"2005","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"clansys","cpe5":"clansys","cpe6":"1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"2005","cve":"CVE-2006-2005","epss":"0.106150000","percentile":"0.933190000","score_date":"2026-04-20","updated_at":"2026-04-21 00:07:48"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:35:31.401Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"clansys-index-file-include(25976)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25976"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.nukedx.com/?getxpl=29"},{"name":"20060423 Advisory: Clansys <= 1.1 PHP Code Insertion Vulnerability.","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/431873/100/0/threaded"},{"name":"782","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/782"},{"name":"1015988","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015988"},{"name":"25083","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/25083"},{"name":"17660","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17660"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-04-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"Eval injection vulnerability in index.php in ClanSys 1.1 allows remote attackers to execute arbitrary PHP code via PHP code in the page parameter, as demonstrated by using an \"include\" statement that is injected into the eval statement.  NOTE: this issue has been described as file inclusion by some sources, but that is just one attack; the primary vulnerability is eval injection."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-18T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"clansys-index-file-include(25976)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25976"},{"tags":["x_refsource_MISC"],"url":"http://www.nukedx.com/?getxpl=29"},{"name":"20060423 Advisory: Clansys <= 1.1 PHP Code Insertion Vulnerability.","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/431873/100/0/threaded"},{"name":"782","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/782"},{"name":"1015988","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015988"},{"name":"25083","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/25083"},{"name":"17660","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17660"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-2005","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Eval injection vulnerability in index.php in ClanSys 1.1 allows remote attackers to execute arbitrary PHP code via PHP code in the page parameter, as demonstrated by using an \"include\" statement that is injected into the eval statement.  NOTE: this issue has been described as file inclusion by some sources, but that is just one attack; the primary vulnerability is eval injection."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"clansys-index-file-include(25976)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25976"},{"name":"http://www.nukedx.com/?getxpl=29","refsource":"MISC","url":"http://www.nukedx.com/?getxpl=29"},{"name":"20060423 Advisory: Clansys <= 1.1 PHP Code Insertion Vulnerability.","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/431873/100/0/threaded"},{"name":"782","refsource":"SREASON","url":"http://securityreason.com/securityalert/782"},{"name":"1015988","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015988"},{"name":"25083","refsource":"OSVDB","url":"http://www.osvdb.org/25083"},{"name":"17660","refsource":"BID","url":"http://www.securityfocus.com/bid/17660"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-2005","datePublished":"2006-04-25T10:00:00.000Z","dateReserved":"2006-04-25T00:00:00.000Z","dateUpdated":"2024-08-07T17:35:31.401Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-04-25 12:50:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:clansys:clansys:1.1:*:*:*:*:*:*:*","matchCriteriaId":"7F87471A-70FA-47E5-927E-D2F6CE2C94D8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"2005","Ordinal":"1","Title":"CVE-2006-2005","CVE":"CVE-2006-2005","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"2005","Ordinal":"1","NoteData":"Eval injection vulnerability in index.php in ClanSys 1.1 allows remote attackers to execute arbitrary PHP code via PHP code in the page parameter, as demonstrated by using an \"include\" statement that is injected into the eval statement.  NOTE: this issue has been described as file inclusion by some sources, but that is just one attack; the primary vulnerability is eval injection.","Type":"Description","Title":"CVE-2006-2005"},{"CveYear":"2006","CveId":"2005","Ordinal":"2","NoteData":"2006-04-25","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"2005","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}