TROYANOSYVIRUS
Back to CVEs

CVE-2006-4904

N/A

Description

Dynamic variable evaluation vulnerability in cmpi.php in Qualiteam X-Cart 4.1.3 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code, as demonstrated by PHP remote file inclusion via the xcart_dir parameter.

CVE Details

CVSS v3.1 ScoreN/A
Published9/21/2006
Last Modified4/16/2026
Sourcenvd
Honeypot Sightings0

Affected Products

qualiteam:x-cart

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.