CVE-2006-2811
Cantico Ovidentia 5.8.0 - Remote File Inclusion via babInstallPath Parameter
Title source: llmExploitation Summary
EIP tracks 8 public exploits for CVE-2006-2811. PoCs published by black-cod3.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Ovidentia due to improper input sanitization. An attacker can include arbitrary remote PHP files, leading to remote code execution in the context of the webserver process.
Description
Multiple PHP remote file inclusion vulnerabilities in Cantico Ovidentia 5.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the babInstallPath parameter in (1) index.php, (2) topman.php, (3) approb.php, (4) vacadmb.php, (5) vacadma.php, (6) vacadm.php, (7) statart.php, (8) search.php, (9) posts.php, (10) options.php, (11) login.php, (12) frchart.php, (13) flbchart.php, (14) fileman.php, (15) faq.php, (16) event.php, (17) directory.php, (18) articles.php, (19) artedit.php, (20) calday.php, and additional unspecified PHP scripts. NOTE: the utilit.php vector is already covered by CVE-2005-1964.
Exploits (8)
This exploit demonstrates a remote file inclusion vulnerability in Ovidentia due to improper input sanitization. An attacker can include arbitrary remote PHP files, leading to remote code execution in the context of the webserver process.
This exploit demonstrates a remote file inclusion vulnerability in Ovidentia due to improper input sanitization. An attacker can include arbitrary remote PHP files, leading to remote code execution in the context of the webserver process.
This exploit demonstrates a remote file inclusion vulnerability in Ovidentia due to improper input sanitization. An attacker can include arbitrary remote PHP files by manipulating the 'babInstallPath' parameter.
This exploit demonstrates a remote file inclusion vulnerability in Ovidentia due to improper input sanitization. An attacker can include arbitrary remote PHP files, leading to remote code execution in the context of the webserver process.
This exploit demonstrates a remote file inclusion vulnerability in Ovidentia by injecting a malicious URL into the 'babInstallPath' parameter. The vulnerability allows arbitrary PHP code execution in the context of the webserver process.
This exploit demonstrates a remote file inclusion vulnerability in Ovidentia due to improper input sanitization. An attacker can include arbitrary remote PHP files, leading to remote code execution in the context of the webserver.
This exploit leverages a remote file inclusion vulnerability in Ovidentia due to improper input sanitization. An attacker can include arbitrary remote PHP files, leading to remote code execution in the context of the webserver process.
This exploit leverages a remote file inclusion vulnerability in Ovidentia due to improper input sanitization. An attacker can include arbitrary remote PHP files, leading to remote code execution in the context of the webserver process.