the master (nidhal)

2 exploits Active since Oct 2006
CVE-2006-5506 EXPLOITDB text WORKING POC
WiClear 0.10 - Remote Code Execution via Path Parameter in Multiple PHP Scripts
Multiple PHP remote file inclusion vulnerabilities in WiClear 0.10 allow remote attackers to execute arbitrary PHP code via the path parameter in (1) inc/prepend.inc.php, (2) inc/lib/boxes.lib.php, (3) inc/lib/tools.lib.php, (4) tools/trackback/index.php, and (5) tools/utf8conversion/index.php in admin/; and (6) prepend.inc.php, (7) lib/boxes.lib.php, and (8) lib/history.lib.php in inc/.
CVE-2006-5523 EXPLOITDB text WORKING POC
ez-ticket 0.0.1 - Remote File Inclusion via ezt_root_path Parameter
PHP remote file inclusion vulnerability in common.php in EZ-Ticket 0.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the ezt_root_path parameter.