CVE-2006-4207
Bob Jewell Discloser < 0.0.4 - Remote File Inclusion via fileloc Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4207. PoCs published by Arash RJ.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in discloser 0.0.4, allowing an attacker to include and execute arbitrary remote PHP files via the 'fileloc' parameter in 'content.php' and 'indexhead.php'.
Description
Multiple PHP remote file inclusion vulnerabilities in Bob Jewell Discloser 0.0.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the fileloc parameter to (1) content/content.php or (2) /inc/indexhead.php.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in discloser 0.0.4, allowing an attacker to include and execute arbitrary remote PHP files via the 'fileloc' parameter in 'content.php' and 'indexhead.php'.