CVE-2006-1154
Fantastic News 2.1.2 and 2.1.4 - Remote File Inclusion via CONFIG[script_path] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-1154. PoCs published by Mr-m07.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Fantastic News <= 2.1.4. The vulnerability arises from insecure usage of the CONFIG[script_path] parameter in archive.php and headlines.php, allowing remote file execution.
Description
PHP remote file inclusion vulnerability in archive.php in Fantastic News 2.1.2 allows remote attackers to include arbitrary files via the CONFIG[script_path] variable. NOTE: 2.1.4 was also reported to be vulnerable.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Fantastic News <= 2.1.4. The vulnerability arises from insecure usage of the CONFIG[script_path] parameter in archive.php and headlines.php, allowing remote file execution.