### [CVE-2006-4752](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4752) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5.1 allows remote attackers to obtain the installation path via a query to the engine module, probably with an invalid action parameter. ### POC #### Reference - http://securityreason.com/securityalert/1565 #### Github No PoCs found on GitHub currently.