Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-2982. PoCs published by Kacper.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Enterprise TimeSheet and Payroll (EPS) v1.1 or earlier. The vulnerability allows an attacker to include arbitrary remote scripts via the 'absolutepath' parameter in footer.php.
Description
Multiple PHP remote file inclusion vulnerabilities in Enterprise Timesheet and Payroll Systems (EPS) 1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absolutepath parameter in (1) footer.php and (2) admin/footer.php.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in Enterprise TimeSheet and Payroll (EPS) v1.1 or earlier. The vulnerability allows an attacker to include arbitrary remote scripts via the 'absolutepath' parameter in footer.php.