CVE-2006-2843
Redaxo 2.7.4 - Remote File Inclusion via REX[INCLUDE_PATH] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2843. PoCs published by beford.
AI-analyzed exploit summary The exploit demonstrates a local file inclusion (LFI) vulnerability in Redaxo CMS versions 2.7.4 to 3.2 by manipulating the REX[INCLUDE_PATH] parameter to include arbitrary files. The attack vectors are provided for multiple endpoints across different versions.
Description
PHP remote file inclusion vulnerability in Redaxo 2.7.4 allows remote attackers to execute arbitrary PHP code via a URL in the (1) REX[INCLUDE_PATH] parameter in (a) addons/import_export/pages/index.inc.php and (b) pages/community.inc.php.
Exploits (1)
The exploit demonstrates a local file inclusion (LFI) vulnerability in Redaxo CMS versions 2.7.4 to 3.2 by manipulating the REX[INCLUDE_PATH] parameter to include arbitrary files. The attack vectors are provided for multiple endpoints across different versions.