Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-1994. PoCs published by nukedx.
AI-analyzed exploit summary This is a writeup detailing multiple remote file inclusion vulnerabilities in dForum <= 1.5. It lists affected files and parameters but does not include functional exploit code.
Description
PHP remote file inclusion vulnerability in dForum 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DFORUM_PATH parameter to (1) about.php, (2) admin.php, (3) anmelden.php, (4) losethread.php, (5) config.php, (6) delpost.php, (7) delthread.php, (8) dfcode.php, (9) download.php, (10) editanoc.php, (11) forum.php, (12) login.php, (13) makethread.php, (14) menu.php, (15) newthread.php, (16) openthread.php, (17) overview.php, (18) post.php, (19) suchen.php, (20) user.php, (21) userconfig.php, (22) userinfo.php, and (23) verwalten.php.
Exploits (1)
This is a writeup detailing multiple remote file inclusion vulnerabilities in dForum <= 1.5. It lists affected files and parameters but does not include functional exploit code.