CVE-2006-2683
open-medium_cms 0.25 - Remote File Inclusion via REDSYS[MYPATH][TEMPLATES] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2683. PoCs published by Kacper.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in open-medium CMS 0.25. The vulnerability arises from improper input validation in the 404.php file, allowing an attacker to include arbitrary remote scripts via the REDSYS[MYPATH][TEMPLATES] parameter.
Description
PHP remote file inclusion vulnerability in 404.php in open-medium.CMS 0.25 allows remote attackers to execute arbitrary PHP code via a URL in the REDSYS[MYPATH][TEMPLATES] parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in open-medium CMS 0.25. The vulnerability arises from improper input validation in the 404.php file, allowing an attacker to include arbitrary remote scripts via the REDSYS[MYPATH][TEMPLATES] parameter.