CVE-2006-2523
phpListPro < 2.0.1 - Remote File Inclusion via Language Cookie
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2523. PoCs published by [Oo].
AI-analyzed exploit summary This exploit targets a local file inclusion vulnerability in phpListPro <= 2.0.1, allowing remote command execution by injecting PHP code into Apache log files. It requires magic_quotes_gpc to be disabled and leverages log poisoning to achieve RCE.
Description
PHP remote file inclusion vulnerability in config.php in phpListPro 2.0.1 and earlier, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary PHP code via a URL in the Language cookie.
Exploits (1)
This exploit targets a local file inclusion vulnerability in phpListPro <= 2.0.1, allowing remote command execution by injecting PHP code into Apache log files. It requires magic_quotes_gpc to be disabled and leverages log poisoning to achieve RCE.