CVE-2006-2323
phpListPro < 2.01 - Remote File Inclusion via returnpath Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2323. PoCs published by Aesthetico.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in phpListPro <= 2.01. The vulnerability allows an attacker to include and execute arbitrary remote files by manipulating the 'returnpath' parameter in multiple scripts.
Description
Multiple PHP remote file inclusion vulnerabilities in SmartISoft phpListPro 2.01 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the returnpath parameter in (1) editsite.php, (2) addsite.php, and (3) in.php. NOTE: The config.php vector is already covered by CVE-2006-1749.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in phpListPro <= 2.01. The vulnerability allows an attacker to include and execute arbitrary remote files by manipulating the 'returnpath' parameter in multiple scripts.