← Vulnerability feed

Vulnerability record · CVE-2006-0144 · published 9 January 2006

CVE-2006-0144: Apache2triad code injection vulnerability

Apache2triad · Apache2triad

The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malicious extractModify function.

7.5 CVSS 2.0 High EPSS 1.8% · top 22.0% CWE-94 · Code injection
7.5CVSS 2.0 base score
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malicious extractModify function.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-0144 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-12965Apache2triad vulnerabilitySession fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.EPSS 16%8.8CVE-2017-12970Apache2triad cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack the authentication of authenticated users for…EPSS 2.2%7.5CVE-2017-5630Php pear injection vulnerabilityPECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which al…EPSS 13%6.1CVE-2017-12971Apache2triad cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the account paramet…EPSS 2.6%5.1CVE-2005-4154Php pear vulnerabilityUnspecified vulnerability in PEAR installer 1.4.2 and earlier allows user-assisted attackers to execute arbitrary code via a crafted package that can…EPSS 7.4%3.3CVE-2011-1072Php pear link following vulnerabilityThe installer in PEAR before 1.9.2 allows local users to overwrite arbitrary files via a symlink attack on the package.xml file, related to the (1) d…EPSS 0.48%3.3CVE-2011-1144Php pear link following vulnerabilityThe installer in PEAR 1.9.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the package.xml file, related to the …EPSS 0.31%8.8CVE-2026-65660Microsoft sharepoint server code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.KEVEPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2006-0144), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.