Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2006-2686

31
FAUCET Score

CVE-2006-2686 describes multiple remote file inclusion vulnerabilities in ActionApps 2.8.1, allowing remote attackers to execute arbitrary PHP code. This vulnerability stems from improper handling of the GLOBALS[AA_INC_PATH] parameter across numerous PHP files within the application. With a CVSS score of 6.4, it is considered medium severity, requiring no authentication and having low attack complexity, potentially leading to partial compromise of confidentiality and integrity. While not actively exploited in the wild (no KEV entry), public exploit code is available via ExploitDB, indicating a clear path for attackers. Despite this, there is minimal community discussion or media coverage surrounding this older vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
2.8.1CPE matchmatch criteria
cpe:2.3:a:actionapps:actionapps:2.8.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.4MEDIUM

AV:N/AC:L/Au:N/C:P/I:P/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
4.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
13.63%
Probability of exploitation in next 30 days
EPSS Percentile
96.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-1829 · May 25, 2006
This CVE's current EPSS score of 0.1363 is in the 95th percentile among its peer group of 23,701 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

secunia.com / advisories/20299
ExploitVendor Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/26776
exploit-db.com / exploits/1829
osvdb.org / 27253
osvdb.org / 27254
osvdb.org / 27256
osvdb.org / 27257
osvdb.org / 27258
osvdb.org / 27259
osvdb.org / 27260
osvdb.org / 27261
osvdb.org / 27262
osvdb.org / 27263
osvdb.org / 27264
osvdb.org / 27265
osvdb.org / 27266
osvdb.org / 27267
osvdb.org / 27268
osvdb.org / 27269
osvdb.org / 27270
osvdb.org / 27271
osvdb.org / 27272
osvdb.org / 27273
osvdb.org / 27274
osvdb.org / 27275
osvdb.org / 27276
osvdb.org / 27277
osvdb.org / 27278
osvdb.org / 27279
osvdb.org / 27280
osvdb.org / 27281
osvdb.org / 27282
osvdb.org / 27283
osvdb.org / 27284
osvdb.org / 27285
osvdb.org / 27286
osvdb.org / 27287
osvdb.org / 27288
osvdb.org / 27289
osvdb.org / 27290
osvdb.org / 27291
osvdb.org / 27292
osvdb.org / 27293
osvdb.org / 27294
osvdb.org / 27295
osvdb.org / 27296
osvdb.org / 27297
osvdb.org / 27298
osvdb.org / 27299
osvdb.org / 27300
osvdb.org / 27301
osvdb.org / 27302
osvdb.org / 27303
osvdb.org / 27304
osvdb.org / 27305
osvdb.org / 27306
osvdb.org / 27308
osvdb.org / 27309
osvdb.org / 27310
securityfocus.com / bid/19133
vupen.com / english/advisories/2006/1997