CVE-2006-2528
phpBazar 2.1.0 - Remote File Inclusion via Language_dir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2528. PoCs published by [Oo].
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in phpBazar <= 2.1.0, allowing arbitrary command execution via a malicious URL parameter. It also includes an admin credential access method through direct parameter manipulation.
Description
PHP remote file inclusion vulnerability in classified_right.php in phpBazar 2.1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the language_dir parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in phpBazar <= 2.1.0, allowing arbitrary command execution via a malicious URL parameter. It also includes an admin credential access method through direct parameter manipulation.