Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-2730. PoCs published by Kacper.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in HOT (Hot Open Tickets) by manipulating the GLOBALS[CLASS_PATH] parameter to include arbitrary remote scripts. The vulnerability allows an attacker to execute arbitrary code on the target system.
Description
PHP remote file inclusion vulnerability in admin/lib_action_step.php in Hot Open Tickets (HOT) 11012004_ver2f, when register_globals is enabled, allows remote attackers to include arbitrary files via the GLOBALS[CLASS_PATH] parameter. NOTE: this issue might be resultant from a global overwrite vulnerability.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in HOT (Hot Open Tickets) by manipulating the GLOBALS[CLASS_PATH] parameter to include arbitrary remote scripts. The vulnerability allows an attacker to execute arbitrary code on the target system.