CVE-2006-3847
MoSpray 1.8 RC1 - Remote Code Execution via basedir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-3847. PoCs published by Kurdish Security.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in MoSpray, allowing an attacker to include arbitrary files via the 'basedir' parameter. The PoC provides a URL structure to execute commands by including a remote file containing malicious code.
Description
PHP remote file inclusion vulnerability in (1) admin.php, and possibly (2) details.php, (3) modify.php, (4) newgroup.php, (5) newtask.php, and (6) rss.php, in MoSpray (aka com_mospray) 1.8 RC1 allows remote attackers to execute arbitrary PHP code via a URL in the basedir parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in MoSpray, allowing an attacker to include arbitrary files via the 'basedir' parameter. The PoC provides a URL structure to execute commands by including a remote file containing malicious code.