CVE-2006-4158
spaminator < 1.7 - Remote File Inclusion via Login.php Page Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4158. PoCs published by Drago84.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Spaminator 1.7. The vulnerability arises from unsanitized user input in the `$page` parameter, allowing an attacker to include arbitrary remote PHP files.
Description
PHP remote file inclusion vulnerability in Login.php in Spaminator 1.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in Spaminator 1.7. The vulnerability arises from unsanitized user input in the `$page` parameter, allowing an attacker to include arbitrary remote PHP files.