CVE-2006-4276
tutti_nova < 1.6 - Remote File Inclusion via TNLIB_DIR Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4276. PoCs published by SHiKaA.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Tutti Nova <= v1.6 by manipulating the TNLIB_DIR parameter to include arbitrary remote files. The vulnerability exists in include/novalib/class.novaEdit.mysql.php due to improper input validation.
Description
PHP remote file inclusion vulnerability in Tutti Nova 1.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to novalib/class.novaEdit.mysql.php.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in Tutti Nova <= v1.6 by manipulating the TNLIB_DIR parameter to include arbitrary remote files. The vulnerability exists in include/novalib/class.novaEdit.mysql.php due to improper input validation.