Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2006-5911

29
FAUCET Score

CVE-2006-5911 describes multiple remote file inclusion vulnerabilities in Campware Campsite versions prior to 2.6.2. Attackers can exploit these flaws by manipulating the g_documentRoot parameter in numerous PHP scripts to execute arbitrary PHP code. With a CVSS score of 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P), this vulnerability is considered highly severe, allowing for full compromise of confidentiality, integrity, and availability without authentication. While not listed on the KEV catalog, multiple public exploits are available on ExploitDB, indicating a clear path for exploitation, though community and media attention remain low.

Impacted Technologies

VendorProductVersion(s)CPE
2.6.0CPE matchmatch criteria
cpe:2.3:a:campware.org:campsite:2.6.0:*:*:*:*:*:*:*
2.6.1CPE matchmatch criteria
cpe:2.3:a:campware.org:campsite:2.6.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
4.44%
Probability of exploitation in next 30 days
EPSS Percentile
90.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-30003 · May 8, 2007
This CVE's current EPSS score of 0.0444 is in the 83rd percentile among its peer group of 51,485 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

code.campware.org / projects/campsite/changeset/6057
Patch
code.campware.org / projects/campsite/changeset/6058
Patch
code.campware.org / projects/campsite/query
code.campware.org / projects/campsite/ticket/2349
sourceforge.net / project/shownotes.php
Patch
osvdb.org / 34187
osvdb.org / 34188
osvdb.org / 34189
osvdb.org / 34190
osvdb.org / 34191
osvdb.org / 34192
osvdb.org / 34193
osvdb.org / 34194
osvdb.org / 34195
osvdb.org / 34196
osvdb.org / 34197
osvdb.org / 34198
osvdb.org / 34199
osvdb.org / 34200
osvdb.org / 34201
osvdb.org / 34202
osvdb.org / 34203
osvdb.org / 34204
osvdb.org / 34205
osvdb.org / 34206
osvdb.org / 34207
osvdb.org / 34208
osvdb.org / 34209
osvdb.org / 34210
osvdb.org / 34211
osvdb.org / 34212
osvdb.org / 34213
osvdb.org / 34214
osvdb.org / 34215
osvdb.org / 34216
osvdb.org / 34217
osvdb.org / 34218
osvdb.org / 34219
osvdb.org / 34220
osvdb.org / 34221
osvdb.org / 34222
osvdb.org / 34223
osvdb.org / 34224
osvdb.org / 34225
securityfocus.com / bid/23874