CVE-2006-2002
MyGamingLadder 7.0 - Remote File Inclusion via stats.php dir[base] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2002. PoCs published by nukedx.
AI-analyzed exploit summary This exploit targets a remote command execution vulnerability in My Gaming Ladder Combo System <= 7.0 by manipulating the 'dir[func]' and 'dir[base]' parameters in 'stats.php' to execute arbitrary commands. It sends an HTTP GET request with a crafted payload to trigger the vulnerability.
Description
PHP remote file inclusion vulnerability in stats.php in MyGamingLadder 7.0 allows remote attackers to execute arbitrary PHP code via a URL in the dir[base] parameter.
Exploits (1)
This exploit targets a remote command execution vulnerability in My Gaming Ladder Combo System <= 7.0 by manipulating the 'dir[func]' and 'dir[base]' parameters in 'stats.php' to execute arbitrary commands. It sends an HTTP GET request with a crafted payload to trigger the vulnerability.