Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-3689. PoCs published by Chironex Fleckeri.
AI-analyzed exploit summary The code describes a remote file inclusion vulnerability in SubberZ[Lite] due to improper input sanitization in the 'myadmindir' parameter. An attacker can exploit this to execute arbitrary PHP code by including a remote file.
Description
PHP remote file inclusion vulnerability in user-func.php in Codeworks Gnomedia SubberZ[Lite] allows remote attackers to execute arbitrary PHP code via a URL in the myadmindir parameter. NOTE: this issue has been disputed by a third party that claims that " the myadmindir variable is set before any GET variables are processed.
Exploits (1)
The code describes a remote file inclusion vulnerability in SubberZ[Lite] due to improper input sanitization in the 'myadmindir' parameter. An attacker can exploit this to execute arbitrary PHP code by including a remote file.