CVE-2006-0214
ezDatabase 2.0 and earlier - Remote Code Execution via db_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-0214. PoCs published by cijfer.
AI-analyzed exploit summary This exploit targets a remote command execution vulnerability in ezDatabase by injecting malicious PHP code via the 'visitorupload.php' script. It uses URL-encoded payloads to execute arbitrary commands and retrieve output.
Description
Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the db_id parameter to visitorupload.php, as demonstrated using phpinfo and include function calls.
Exploits (1)
This exploit targets a remote command execution vulnerability in ezDatabase by injecting malicious PHP code via the 'visitorupload.php' script. It uses URL-encoded payloads to execute arbitrary commands and retrieve output.