Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-4077. PoCs published by Philipp Niedziela.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Cwfm 0.9.1 due to improper sanitization of the 'Language' parameter in CheckUpload.php. An attacker can include a remote file containing malicious code, leading to Remote Code Execution (RCE).
Description
PHP remote file inclusion vulnerability in CheckUpload.php in Vincenzo Valvano Comet WebFileManager (CWFM) 0.9.1, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the Language parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Cwfm 0.9.1 due to improper sanitization of the 'Language' parameter in CheckUpload.php. An attacker can include a remote file containing malicious code, leading to Remote Code Execution (RCE).