CVE-2006-3421
SmartSiteCMS < 1.0 - Remote File Inclusion via Root Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2006-3421. PoCs published by CrAsh_oVeR_rIdE, Archit3ct.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Smartsite CMS v1.0. The vulnerability arises from insecure handling of the 'root' parameter in multiple PHP files, allowing an attacker to include arbitrary remote files.
Description
PHP remote file inclusion vulnerability in SmartSiteCMS 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the root parameter in (1) comment.php, (2) admin/comedit.php, (3) admin/test.php, (4) admin/index.php, and (5) admin/include/inc_adminfoot.php, a different set of vectors than CVE-2006-3162.
Exploits (2)
This exploit demonstrates a remote file inclusion vulnerability in Smartsite CMS v1.0. The vulnerability arises from insecure handling of the 'root' parameter in multiple PHP files, allowing an attacker to include arbitrary remote files.
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in SmartSite CMS <= 1.0 by manipulating the 'root' parameter in 'inc.foot.php' to include arbitrary remote files. The vulnerable code dynamically includes a file path constructed from user-controlled input without proper validation.