Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-3556. PoCs published by Matdhule.
AI-analyzed exploit summary The code describes a remote file inclusion vulnerability in ExtCalendar 2.0 due to improper input sanitization. An attacker can exploit this by manipulating the 'mosConfig_absolute_path' parameter to include and execute arbitrary PHP code from a remote server.
Description
PHP remote file inclusion vulnerability in extcalendar.php in Mohamed Moujami ExtCalendar 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Exploits (1)
The code describes a remote file inclusion vulnerability in ExtCalendar 2.0 due to improper input sanitization. An attacker can exploit this by manipulating the 'mosConfig_absolute_path' parameter to include and execute arbitrary PHP code from a remote server.