CVE-2006-2726
Fastpublish CMS 1.6.9.d - Remote File Inclusion via config[fsBase] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2726. PoCs published by Kacper.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Fastpublish CMS v1.6.9.d by manipulating the 'config[fsBase]' parameter in multiple scripts. An attacker can include and execute arbitrary remote scripts, leading to potential remote code execution.
Description
PHP remote file inclusion vulnerability in Fastpublish CMS 1.6.9.d allows remote attackers to include arbitrary files via the config[fsBase] parameter in (1) drucken.php, (2) drucken2.php, (3) email_an_benutzer.php, (4) rechnung.php, (5) suche/search.php and (6) adminbereich/admin.php.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in Fastpublish CMS v1.6.9.d by manipulating the 'config[fsBase]' parameter in multiple scripts. An attacker can include and execute arbitrary remote scripts, leading to potential remote code execution.