CVE-2006-2852
dotwidget_cms 1.0.6 - Remote Code Execution via file_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2852. PoCs published by Aesthetico.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in dotWidget CMS <= 1.0.6, allowing an attacker to include and execute arbitrary remote PHP scripts via the 'file_path' parameter in multiple endpoints.
Description
PHP remote file inclusion vulnerability in dotWidget CMS 1.0.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the file_path parameter in (1) index.php, (2) feedback.php, and (3) printfriendly.php.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in dotWidget CMS <= 1.0.6, allowing an attacker to include and execute arbitrary remote PHP scripts via the 'file_path' parameter in multiple endpoints.