CVE-2006-4230
Lizge V.20 Web Portal - Remote File Inclusion via lizge or bade Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4230. PoCs published by Crackers_Child.
AI-analyzed exploit summary The provided text describes a remote file inclusion vulnerability in Lizge V.20, where unsanitized user input allows arbitrary remote file inclusion and execution of malicious PHP code. The example URLs demonstrate how an attacker could exploit this to execute commands via a remote file.
Description
Multiple PHP remote file inclusion vulnerabilities in index.php in Lizge V.20 Web Portal allow remote attackers to execute arbitrary PHP code via a URL in the (1) lizge or (2) bade parameters.
Exploits (1)
The provided text describes a remote file inclusion vulnerability in Lizge V.20, where unsanitized user input allows arbitrary remote file inclusion and execution of malicious PHP code. The example URLs demonstrate how an attacker could exploit this to execute commands via a remote file.