Exploitation Summary
EIP tracks 1 public exploit for CVE-2005-0792. PoCs published by Mikhail.
AI-analyzed exploit summary The exploit demonstrates arbitrary file inclusion vulnerabilities in ZPanel versions 2.0 and 2.5 beta 10. For version 2.0, it allows remote file inclusion via a malicious URL, while for version 2.5 beta, it uses a null byte and SQL injection to bypass restrictions.
Description
SQL injection vulnerability in ZPanel 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter to index.php or (2) page parameter to zpanel.php.
Exploits (1)
The exploit demonstrates arbitrary file inclusion vulnerabilities in ZPanel versions 2.0 and 2.5 beta 10. For version 2.0, it allows remote file inclusion via a malicious URL, while for version 2.5 beta, it uses a null byte and SQL injection to bypass restrictions.