CVE-2006-3966
MyNewsGroups :) < 0.6b - Remote Code Execution via myng_root Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-3966. PoCs published by Philipp Niedziela.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in MyNewsGroups v. 0.6b due to improper sanitization of the $myng_root variable in layersmenue.inc.php. An attacker can include a remote PHP shell by manipulating the myng_root parameter.
Description
PHP remote file inclusion vulnerability in /lib/tree/layersmenu.inc.php in the PHP Layers Menu 2.3.5 package for MyNewsGroups :) 0.6b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myng_root parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in MyNewsGroups v. 0.6b due to improper sanitization of the $myng_root variable in layersmenue.inc.php. An attacker can include a remote PHP shell by manipulating the myng_root parameter.