CVE-2006-4277
tutti_nova < 1.6 - Remote File Inclusion via TNLIB_DIR Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4277. PoCs published by SHiKaA.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Tutti Nova <= v1.6 by manipulating the TNLIB_DIR parameter to include arbitrary remote files. The vulnerability exists in include/novalib/class.novaEdit.mysql.php due to improper input validation.
Description
Multiple PHP remote file inclusion vulnerabilities in Tutti Nova 1.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to (1) include/novalib/class.novaAdmin.mysql.php and (2) novalib/class.novaRead.mysql.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in Tutti Nova <= v1.6 by manipulating the TNLIB_DIR parameter to include arbitrary remote files. The vulnerability exists in include/novalib/class.novaEdit.mysql.php due to improper input validation.