Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2006-5020

33
FAUCET Score

CVE-2006-5020 describes multiple remote file inclusion vulnerabilities in SolidState 0.4 and earlier. Attackers can execute arbitrary PHP code by manipulating the base_path parameter in numerous manager/pages/ scripts and modules. This vulnerability has a CVSS score of 7.5, indicating high severity due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an exploit is publicly available on ExploitDB, and the FAUCET Risk Score is 93/100. Community discussion and media coverage for this CVE are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
<= 0.4CPE matchmatch criteria
cpe:2.3:a:solidstate:solidstate:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
10.60%
Probability of exploitation in next 30 days
EPSS Percentile
95.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-2413 · Sep 21, 2006
This CVE's current EPSS score of 0.1060 is in the 93rd percentile among its peer group of 51,485 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

attrition.org / pipermail/vim/2007-January/001210.html
exchange.xforce.ibmcloud.com / vulnerabilities/29095
exploit-db.com / exploits/2413
osvdb.org / 31097
osvdb.org / 31098
osvdb.org / 31099
osvdb.org / 31100
osvdb.org / 31104
osvdb.org / 31105
osvdb.org / 31106
osvdb.org / 31107
osvdb.org / 31108
osvdb.org / 31109
osvdb.org / 31110
osvdb.org / 31111
osvdb.org / 31112
osvdb.org / 31113
osvdb.org / 31114
osvdb.org / 31115
osvdb.org / 31116
osvdb.org / 31117
osvdb.org / 31118
osvdb.org / 31119
osvdb.org / 31120
osvdb.org / 31121
osvdb.org / 31122
osvdb.org / 31123
osvdb.org / 31124
osvdb.org / 31125
osvdb.org / 31126
osvdb.org / 31127
osvdb.org / 31128
osvdb.org / 31129
osvdb.org / 31130
osvdb.org / 31131
osvdb.org / 31132
osvdb.org / 31133
osvdb.org / 31134
osvdb.org / 31135
osvdb.org / 31136
osvdb.org / 31137
osvdb.org / 31138
osvdb.org / 31139
osvdb.org / 31141
osvdb.org / 31142
osvdb.org / 31143
osvdb.org / 31144
osvdb.org / 31145
osvdb.org / 31146
osvdb.org / 31147
osvdb.org / 31190
osvdb.org / 31191
osvdb.org / 31192
osvdb.org / 31193
osvdb.org / 31194
osvdb.org / 31197
osvdb.org / 31198
osvdb.org / 31199
osvdb.org / 31200
osvdb.org / 31201
osvdb.org / 31202
osvdb.org / 31203
securityfocus.com / bid/21934
solid-state.org / index.php