AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2006-0183

MEDIUM · CVSS 6.5 EPSS 1.32%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2006-01-12 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2006-0183
Severity
MEDIUM
CVSS
6.5
EPSS
1.32%

Original NVD Description

Direct static code injection vulnerability in edit.php in ACal Calendar Project 2.2.5 allows authenticated users to execute arbitrary PHP code via (1) the edit=header value, which modifies header.php, or (2) the edit=footer value, which modifies footer.php. NOTE: this issue might be resultant from the poor authentication as identified by CVE-2006-0182. Since the design of the product allows the administrator to edit the code, perhaps this issue should not be included in CVE, except as a consequence of CVE-2006-0182.