CVE-2006-0899
4images image_gallery_management_system < 1.7.1 - Directory Traversal via Template Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-0899. PoCs published by rgod.
AI-analyzed exploit summary This exploit targets a directory traversal and arbitrary local file inclusion vulnerability in 4Images <= 1.7.1. It uploads a malicious .jpg file with EXIF metadata containing PHP code, then executes it via the vulnerable 'template' parameter.
Description
Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include arbitrary files via ".." (dot dot) sequences in the template parameter.
Exploits (1)
This exploit targets a directory traversal and arbitrary local file inclusion vulnerability in 4Images <= 1.7.1. It uploads a malicious .jpg file with EXIF metadata containing PHP code, then executes it via the vulnerable 'template' parameter.