CVE-2005-2162
MyGuestbook 0.6.1 - Remote File Inclusion via Lang Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-2162. PoCs published by SoulBlack Group.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in MyGuestbook due to improper input sanitization. An attacker can execute arbitrary server-side script code by manipulating the 'lang' parameter to include a remote file containing malicious commands.
Description
PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in MyGuestbook due to improper input sanitization. An attacker can execute arbitrary server-side script code by manipulating the 'lang' parameter to include a remote file containing malicious commands.