CVE-2006-2557
Florian Amrhein NewsPortal < 0.37 - Remote File Inclusion via file_newsportal Parameter
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2557. PoCs published by Kacper.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in TR Newsportal via the 'file_newsportal' parameter in 'extras/poll/poll.php'. The vulnerability allows an attacker to include and execute arbitrary remote scripts by manipulating the parameter.
Description
PHP remote file inclusion vulnerability in extras/poll/poll.php in Florian Amrhein NewsPortal before 0.37, and TR Newsportal (TRanx rebuilded), allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in TR Newsportal via the 'file_newsportal' parameter in 'extras/poll/poll.php'. The vulnerability allows an attacker to include and execute arbitrary remote scripts by manipulating the parameter.