Record summary

CVE-2006-4163 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.

Description

PHP remote file inclusion vulnerability in cls_fast_template.php in myWebland miniBloggie 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fname parameter. NOTE: another researcher was unable to find a way to execute code after including it via a URL. CVE analysis as of 20060816 was inconclusive

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBminiBloggie 1.0 - 'Fname' Remote File InclusionExploitDB exploitby sh3llNot analyzed1 file
ExploitDB

PoC details

References

4