CVE-2006-3998
WoWRoster 1.5.1 - Remote File Inclusion via conf.php subdir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-3998. PoCs published by skulmatic.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in WoW Roster <= 1.5.1, allowing an attacker to include and execute arbitrary remote files via the 'subdir' parameter in conf.php. The PoC shows a simple command execution example using a remote file.
Description
PHP remote file inclusion vulnerability in conf.php in WoWRoster (aka World of Warcraft Roster) 1.5.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the subdir parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in WoW Roster <= 1.5.1, allowing an attacker to include and execute arbitrary remote files via the 'subdir' parameter in conf.php. The PoC shows a simple command execution example using a remote file.