CVE-2006-1164
Nodez <= 4.6.1.1 - Unauthenticated Sensitive Data Exposure via list.gtdat
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-1164. PoCs published by rgod.
AI-analyzed exploit summary This exploit targets CVE-2006-1164 in Nodez CMS, leveraging arbitrary local file inclusion and admin authentication bypass to execute commands. It injects PHP code into a log file and includes it via path traversal or bypasses authentication using stolen MD5 hashes.
Description
Nodez 4.6.1.1 and earlier stores sensitive data in the list.gtdat file under the web document root with insufficient access control, which allows remote attackers to obtain usernames and password hashes by directly accessing list.gtdat.
Exploits (1)
This exploit targets CVE-2006-1164 in Nodez CMS, leveraging arbitrary local file inclusion and admin authentication bypass to execute commands. It injects PHP code into a log file and includes it via path traversal or bypasses authentication using stolen MD5 hashes.