CVE-2006-4073
phpCC Beta 4.2 - Remote File Inclusion via base_dir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4073. PoCs published by Solpot.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in phpCC Beta 4.2 due to improper verification of the 'base_dir' parameter. Attackers can include arbitrary PHP files from external resources, leading to remote code execution.
Description
Multiple PHP remote file inclusion vulnerabilities in Fabian Hainz phpCC Beta 4.2 allow remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter to (1) login.php, (2) reactivate.php, or (3) register.php.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in phpCC Beta 4.2 due to improper verification of the 'base_dir' parameter. Attackers can include arbitrary PHP files from external resources, leading to remote code execution.