{"api_version":"1","generated_at":"2026-07-23T10:47:15+00:00","cve":"CVE-2006-4636","urls":{"html":"https://cve.report/CVE-2006-4636","api":"https://cve.report/api/cve/CVE-2006-4636.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-4636","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-4636"},"summary":{"title":"CVE-2006-4636","description":"Directory traversal vulnerability in SZEWO PhpCommander 3.0 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Directory parameter, as demonstrated by parameter values naming Apache HTTP Server log files that apparently contain PHP code.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-09-08 20:04:00","updated_at":"2017-10-19 01:29:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://www.exploit-db.com/exploits/2310","name":"2310","refsource":"EXPLOIT-DB","tags":[],"title":"PhpCommander 3.0 - 'upload' Remote Code Execution - PHP webapps Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/21753","name":"21753","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"PhpCommander \"Directory\" Local File Inclusion Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/3472","name":"ADV-2006-3472","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/19867","name":"19867","refsource":"BID","tags":["Exploit"],"title":"SZEWO PhpCommander Download.PHP Local File Include Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-4636","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-4636","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"4636","vulnerable":"1","versionEndIncluding":"3.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"szewo","cpe5":"phpcommander","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-4636","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Directory traversal vulnerability in SZEWO PhpCommander 3.0 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Directory parameter, as demonstrated by parameter values naming Apache HTTP Server log files that apparently contain PHP code."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"21753","refsource":"SECUNIA","url":"http://secunia.com/advisories/21753"},{"name":"2310","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/2310"},{"name":"ADV-2006-3472","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/3472"},{"name":"19867","refsource":"BID","url":"http://www.securityfocus.com/bid/19867"}]}},"nvd":{"publishedDate":"2006-09-08 20:04:00","lastModifiedDate":"2017-10-19 01:29:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:szewo:phpcommander:*:*:*:*:*:*:*:*","versionEndIncluding":"3.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"4636","Ordinal":"19972","Title":"CVE-2006-4636","CVE":"CVE-2006-4636","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"4636","Ordinal":"1","NoteData":"Directory traversal vulnerability in SZEWO PhpCommander 3.0 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Directory parameter, as demonstrated by parameter values naming Apache HTTP Server log files that apparently contain PHP code.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"4636","Ordinal":"2","NoteData":"2006-09-08","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"4636","Ordinal":"3","NoteData":"2017-10-18","Type":"Other","Title":"Modified"}]}}}