Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-3991. PoCs published by SHiKaA.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Voodoo Chat 1.0RC1b. The vulnerability arises from improper input validation in the 'file_path' parameter in index.php, allowing an attacker to include remote files and potentially execute arbitrary code.
Description
PHP remote file inclusion vulnerability in index.php in Vlad Vostrykh Voodoo chat 1.0RC1b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file_path parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Voodoo Chat 1.0RC1b. The vulnerability arises from improper input validation in the 'file_path' parameter in index.php, allowing an attacker to include remote files and potentially execute arbitrary code.