CVE-2006-2995
WebprojectDB <= 0.1.3 - Remote File Inclusion via INCDIR Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2995. PoCs published by Kacper.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in WebprojectDB (INCDIR) <= v0.1.3. The vulnerability allows an attacker to include arbitrary remote scripts via the INCDIR parameter in nav.php or lang.php.
Description
Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the INCDIR parameter in (1) include/nav.php and (2) include/lang.php.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in WebprojectDB (INCDIR) <= v0.1.3. The vulnerability allows an attacker to include arbitrary remote scripts via the INCDIR parameter in nav.php or lang.php.