CVE-2006-4904

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/09/2006
Last modified:
03/04/2025

Description

Dynamic variable evaluation vulnerability in cmpi.php in Qualiteam X-Cart 4.1.3 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code, as demonstrated by PHP remote file inclusion via the xcart_dir parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:qualiteam:x-cart:*:*:*:*:*:*:*:* 4.1.3 (including)