CVE-2006-4011
Kayako eSupport - Remote File Inclusion via autoclose.php subd Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4011. PoCs published by beford.
AI-analyzed exploit summary This exploit leverages a file inclusion vulnerability in Kayako eSupport due to improper handling of the 'subd' parameter in autoclose.php when register_globals is enabled. It allows remote file inclusion (RFI) by injecting a malicious URL, leading to arbitrary code execution.
Description
PHP remote file inclusion vulnerability in esupport/admin/autoclose.php in Kayako eSupport 2.3.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the subd parameter.
Exploits (1)
This exploit leverages a file inclusion vulnerability in Kayako eSupport due to improper handling of the 'subd' parameter in autoclose.php when register_globals is enabled. It allows remote file inclusion (RFI) by injecting a malicious URL, leading to arbitrary code execution.