CVE-2006-0075
GNU phpBook <= 1.3.2 - Remote Code Execution via Email Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-0075. PoCs published by Aliaksandr Hartsuyeu.
AI-analyzed exploit summary This exploit demonstrates a PHP code injection vulnerability in phpBook by injecting arbitrary PHP code via the email field. The vulnerability allows remote attackers to execute arbitrary PHP code when the injected data is processed.
Description
Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via the e-mail field (mail variable) in a new message, which is written to a PHP file.
Exploits (1)
This exploit demonstrates a PHP code injection vulnerability in phpBook by injecting arbitrary PHP code via the email field. The vulnerability allows remote attackers to execute arbitrary PHP code when the injected data is processed.