Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2006-4889

26
FAUCET Score

CVE-2006-4889 describes multiple remote file inclusion vulnerabilities in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, allowing remote attackers to execute arbitrary PHP code. This vulnerability arises when the register_globals setting is enabled, through manipulating the 'dir_path' parameter across numerous PHP files within the application. With a CVSS score of 5.1 and a FAUCET Risk Score of 75/100, this medium-severity flaw could lead to partial compromise of confidentiality, integrity, and availability. While not listed in CISA KEV, multiple public exploits are available on ExploitDB, indicating a clear path for exploitation, though there is no evidence of active exploitation or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.3CPE matchmatch criteria
cpe:2.3:a:telekorn:signkorn_guestbook:*:*:*:*:*:*:*:*
1.1CPE matchmatch criteria
cpe:2.3:a:telekorn:signkorn_guestbook:1.1:*:*:*:*:*:*:*
1.2CPE matchmatch criteria
cpe:2.3:a:telekorn:signkorn_guestbook:1.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.1MEDIUM

AV:N/AC:H/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
HIGH
Authentication
NONE
Exploitability Score
4.9
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
10.17%
Probability of exploitation in next 30 days
EPSS Percentile
95.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-28525 · Sep 12, 2006
This CVE's current EPSS score of 0.1017 is in the 95th percentile among its peer group of 19,954 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

securityreason.com / securityalert/1619
exchange.xforce.ibmcloud.com / vulnerabilities/28888
osvdb.org / 32199
osvdb.org / 32200
osvdb.org / 32201
osvdb.org / 32202
osvdb.org / 32203
osvdb.org / 32204
osvdb.org / 32205
osvdb.org / 32206
osvdb.org / 32207
osvdb.org / 32208
osvdb.org / 32209
osvdb.org / 32210
osvdb.org / 32211
osvdb.org / 32212
osvdb.org / 32213
osvdb.org / 32214
osvdb.org / 32215
osvdb.org / 32216
osvdb.org / 32217
osvdb.org / 32218
securityfocus.com / archive/1/446086/100/0/threaded
securityfocus.com / bid/19977
Exploit
telekorn.com / forum/showthread.php
URL Repurposed