CVE-2006-2485
Quezza BB < 1.0 - Remote File Inclusion via quezza_root_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2485. PoCs published by nukedx.
AI-analyzed exploit summary This exploit demonstrates a file inclusion vulnerability in Quezza BB <= 1.0 via the 'quezza_root_path' parameter in 'class_template.php'. It allows remote file inclusion (RFI) or local file inclusion (LFI) by manipulating the parameter to include arbitrary files or remote URLs.
Description
PHP remote file inclusion vulnerability in includes/class_template.php in Quezza 1.0 and earlier, and possibly 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the quezza_root_path parameter.
Exploits (1)
This exploit demonstrates a file inclusion vulnerability in Quezza BB <= 1.0 via the 'quezza_root_path' parameter in 'class_template.php'. It allows remote file inclusion (RFI) or local file inclusion (LFI) by manipulating the parameter to include arbitrary files or remote URLs.