CVE-2006-2849
Bytehoard 2.1 Epsilon/Delta - Remote File Inclusion via bhconfig[bhfilepath] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2849. PoCs published by beford.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in Bytehoard 2.1 Epsilon/Delta. The vulnerability arises from improper input validation in the 'bhconfig[bhfilepath]' parameter, allowing an attacker to include arbitrary remote files.
Description
PHP remote file inclusion vulnerability in includes/webdav/server.php in Bytehoard 2.1 Epsilon/Delta allows remote attackers to execute arbitrary PHP code via a URL in the bhconfig[bhfilepath] parameter.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in Bytehoard 2.1 Epsilon/Delta. The vulnerability arises from improper input validation in the 'bhconfig[bhfilepath]' parameter, allowing an attacker to include arbitrary remote files.