CVE-2006-4287
NES Game and NES System - Remote File Inclusion via PHPHTMllib Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4287. PoCs published by Kacper.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in NES Game & NES System (phphtmllib) by injecting a remote URL into the 'phphtmllib' parameter. It allows an attacker to execute arbitrary PHP code by including a malicious script from an external server.
Description
Multiple PHP remote file inclusion vulnerabilities in NES Game and NES System c108122 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) phphtmllib parameter to (a) phphtmllib/includes.php; tag_utils/ scripts including (b) divtag_utils.php, (c) form_utils.php, (d) html_utils.php, and (e) localinc.php; and widgets/ scripts including (f) FooterNav.php, (g) HTMLPageClass.php, (h) InfoTable.php, (i) localinc.php, (j) NavTable.php, and (k) TextNav.php.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in NES Game & NES System (phphtmllib) by injecting a remote URL into the 'phphtmllib' parameter. It allows an attacker to execute arbitrary PHP code by including a malicious script from an external server.