CVE-2006-3076
PhpBlueDragon CMS 2.9.1 - Remote File Inclusion via vsDragonRootPath Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-3076. PoCs published by Federico Fazzi.
AI-analyzed exploit summary The advisory describes a file inclusion vulnerability in PhpBlueDragon CMS 2.9.1 due to unsanitized input in the 'vsDragonRootPath' parameter. The PoC demonstrates how an attacker can include arbitrary files by manipulating the parameter.
Description
PHP remote file inclusion vulnerability in software_upload/public_includes/pub_templates/vphptree/template.php in PhpBlueDragon CMS 2.9.1 allows remote attackers to execute arbitrary PHP code via a URL in the vsDragonRootPath parameter.
Exploits (1)
The advisory describes a file inclusion vulnerability in PhpBlueDragon CMS 2.9.1 due to unsanitized input in the 'vsDragonRootPath' parameter. The PoC demonstrates how an attacker can include arbitrary files by manipulating the parameter.