{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-30T21:58:33.036","vulnerabilities":[{"cve":{"id":"CVE-2006-5621","sourceIdentifier":"cve@mitre.org","published":"2006-10-31T20:07:00.000","lastModified":"2026-06-16T22:31:33.150","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"PHP remote file inclusion vulnerability in end.php in ask_rave 0.9 PR, and other versions before 0.9b, allows remote attackers to execute arbitrary PHP code via a URL in the footfile parameter."},{"lang":"es","value":"Vulnerabilidad de inclusión remota de archivo en PHP en end.php de ask_rave 0.9 PR, y otras versiones anteriores a 0.9b, permite a atacantes remotos ejecutar código PHP de su elección mediante un URL en parámetro footfile."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ask_rave:ask_rave:*:*:*:*:*:*:*:*","versionEndIncluding":"0.9_pr","matchCriteriaId":"DB0B18D3-FC28-4349-AE50-F8C56B05F579"}]}]}],"references":[{"url":"http://rave.jk-digital.com/blog/2006/12/08/ask_rave-09b-released/","source":"cve@mitre.org","tags":["Patch"]},{"url":"http://www.securityfocus.com/bid/20758","source":"cve@mitre.org","tags":["Exploit"]},{"url":"http://www.vupen.com/english/advisories/2006/4211","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29825","source":"cve@mitre.org"},{"url":"https://www.exploit-db.com/exploits/2654","source":"cve@mitre.org"},{"url":"http://rave.jk-digital.com/blog/2006/12/08/ask_rave-09b-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"http://www.securityfocus.com/bid/20758","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"]},{"url":"http://www.vupen.com/english/advisories/2006/4211","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29825","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.exploit-db.com/exploits/2654","source":"af854a3a-2127-422b-91ae-364da2661108"}],"evaluatorSolution":"This vulnerability is addressed in the following product update:\r\nask_rave, ask_rave, 0.9b","vendorComments":[{"organization":"Rave","comment":"Ask_rave 0.9b has been released for immediate download and versions 0.9PR and below have been rendered obsolete. All users using versions 0.9PR and prior are recommended to upgrade their versions immediately. Users can use the following URI to download this new version: http://rave.jk-digital.com/site/scripts/ask.php","lastModified":"2006-12-12T00:00:00"}]}}]}