CVE-2006-1784
Sphider 1.3 - Remote Code Execution via settings_dir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-1784. PoCs published by rgod.
AI-analyzed exploit summary This exploit targets a remote file inclusion vulnerability in Sphider <= 1.3. It leverages improper input validation in the 'settings_dir' parameter to include a remote PHP file, enabling arbitrary command execution.
Description
PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the settings_dir parameter.
Exploits (1)
This exploit targets a remote file inclusion vulnerability in Sphider <= 1.3. It leverages improper input validation in the 'settings_dir' parameter to include a remote PHP file, enabling arbitrary command execution.