CVE-2006-3983
php(Reactor) 1.27pl1 - Remote File Inclusion via editprofile.php pathtohomedir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-3983. PoCs published by CeNGiZ-HaN.
AI-analyzed exploit summary This exploit demonstrates a path traversal vulnerability in phpreactor 1.2.7 pl 1, allowing remote inclusion of arbitrary files via the 'pathtohomedir' parameter in editprofile.php. The vulnerability arises from insufficient validation of user-supplied input in include statements.
Description
PHP remote file inclusion vulnerability in editprofile.php in php(Reactor) 1.27pl1 allows remote attackers to execute arbitrary PHP code via a URL in the pathtohomedir parameter.
Exploits (1)
This exploit demonstrates a path traversal vulnerability in phpreactor 1.2.7 pl 1, allowing remote inclusion of arbitrary files via the 'pathtohomedir' parameter in editprofile.php. The vulnerability arises from insufficient validation of user-supplied input in include statements.