{"api_version":"1","generated_at":"2026-07-23T10:55:39+00:00","cve":"CVE-2006-5621","urls":{"html":"https://cve.report/CVE-2006-5621","api":"https://cve.report/api/cve/CVE-2006-5621.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-5621","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-5621"},"summary":{"title":"CVE-2006-5621","description":"PHP remote file inclusion vulnerability in end.php in ask_rave 0.9 PR, and other versions before 0.9b, allows remote attackers to execute arbitrary PHP code via a URL in the footfile parameter.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-10-31 20:07:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-94","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://rave.jk-digital.com/blog/2006/12/08/ask_rave-09b-released/","name":"http://rave.jk-digital.com/blog/2006/12/08/ask_rave-09b-released/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"ask_rave 0.9b released at  rave.jk-digital.com","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/2654","name":"https://www.exploit-db.com/exploits/2654","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ask_rave 0.9 PR - 'end.php?footfile' Remote File Inclusion - PHP webapps Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29825","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29825","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/4211","name":"http://www.vupen.com/english/advisories/2006/4211","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail - OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/20758","name":"http://www.securityfocus.com/bid/20758","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Ask Rave End.PHP Remote File Include Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-5621","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-5621","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"5621","vulnerable":"1","versionEndIncluding":"0.9_pr","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ask_rave","cpe5":"ask_rave","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2006-5621","organization":"Rave","lastmodified":"2006-12-12","contributor":"Peter Graham","statementText":"Ask_rave 0.9b has been released for immediate download and versions 0.9PR and below have been rendered obsolete. All users using versions 0.9PR and prior are recommended to upgrade their versions immediately. Users can use the following URI to download this new version: http://rave.jk-digital.com/site/scripts/ask.php","cve_year":"2006","cve_id":"5621","crc32":"eacaf22f"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T19:55:53.574Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ask-rave-end-file-include(29825)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29825"},{"name":"2654","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/2654"},{"name":"20758","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/20758"},{"name":"ADV-2006-4211","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/4211"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://rave.jk-digital.com/blog/2006/12/08/ask_rave-09b-released/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-10-26T00:00:00.000Z","descriptions":[{"lang":"en","value":"PHP remote file inclusion vulnerability in end.php in ask_rave 0.9 PR, and other versions before 0.9b, allows remote attackers to execute arbitrary PHP code via a URL in the footfile parameter."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-10-18T16:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ask-rave-end-file-include(29825)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29825"},{"name":"2654","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/2654"},{"name":"20758","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/20758"},{"name":"ADV-2006-4211","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/4211"},{"tags":["x_refsource_CONFIRM"],"url":"http://rave.jk-digital.com/blog/2006/12/08/ask_rave-09b-released/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-5621","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"PHP remote file inclusion vulnerability in end.php in ask_rave 0.9 PR, and other versions before 0.9b, allows remote attackers to execute arbitrary PHP code via a URL in the footfile parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ask-rave-end-file-include(29825)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29825"},{"name":"2654","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/2654"},{"name":"20758","refsource":"BID","url":"http://www.securityfocus.com/bid/20758"},{"name":"ADV-2006-4211","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/4211"},{"name":"http://rave.jk-digital.com/blog/2006/12/08/ask_rave-09b-released/","refsource":"CONFIRM","url":"http://rave.jk-digital.com/blog/2006/12/08/ask_rave-09b-released/"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-5621","datePublished":"2006-10-31T20:00:00.000Z","dateReserved":"2006-10-31T00:00:00.000Z","dateUpdated":"2024-08-07T19:55:53.574Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-10-31 20:07:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-94","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ask_rave:ask_rave:*:*:*:*:*:*:*:*","versionEndIncluding":"0.9_pr","matchCriteriaId":"DB0B18D3-FC28-4349-AE50-F8C56B05F579"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"5621","Ordinal":"1","Title":"CVE-2006-5621","CVE":"CVE-2006-5621","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"5621","Ordinal":"1","NoteData":"PHP remote file inclusion vulnerability in end.php in ask_rave 0.9 PR, and other versions before 0.9b, allows remote attackers to execute arbitrary PHP code via a URL in the footfile parameter.","Type":"Description","Title":"CVE-2006-5621"},{"CveYear":"2006","CveId":"5621","Ordinal":"2","NoteData":"2006-10-31","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"5621","Ordinal":"3","NoteData":"2017-10-18","Type":"Other","Title":"Modified"}]}}}