CVE-2006-2405
Unclassified NewsBoard <= 1.6.1_patch1 - Directory Traversal via ABBC[Config][smileset] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2405.
AI-analyzed exploit summary This exploit leverages a local file inclusion vulnerability in Unclassified NewsBoard <= 1.6.1 patch 1 via the ABBC[Config][smileset] parameter. It uploads a malicious avatar containing PHP code and executes arbitrary commands by including the uploaded file.
Description
Directory traversal vulnerability in unb_lib/abbc.conf.php in Unclassified NewsBoard (UNB) 1.6.1 patch 1 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing null byte (%00) in the ABBC[Config][smileset] parameter to unb_lib/abbc.css.php.
Exploits (1)
This exploit leverages a local file inclusion vulnerability in Unclassified NewsBoard <= 1.6.1 patch 1 via the ABBC[Config][smileset] parameter. It uploads a malicious avatar containing PHP code and executes arbitrary commands by including the uploaded file.