CVE-2006-4191
Extreme Message Board < 1.9.6 - Remote File Inclusion via memcp.php langfilenew Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4191. PoCs published by rgod.
AI-analyzed exploit summary This exploit leverages a local file inclusion vulnerability in XMB Forum <= 1.9.6 by bypassing the basename() check via a null byte injection. It injects PHP code into Apache log files and executes arbitrary commands through a crafted profile update.
Description
Directory traversal vulnerability in memcp.php in XMB (Extreme Message Board) 1.9.6 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the langfilenew parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by header.php.
Exploits (1)
This exploit leverages a local file inclusion vulnerability in XMB Forum <= 1.9.6 by bypassing the basename() check via a null byte injection. It injects PHP code into Apache log files and executes arbitrary commands through a crafted profile update.