CVE-2006-4329
Shadows Rising RPG < 0.0.5b_pre-alpha - Remote File Inclusion via CONFIG[gameroot] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4329. PoCs published by Kacper.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in Shadows Rising RPG (Pre-Alpha) <= 0.0.5b. The vulnerability allows an attacker to include remote files via the CONFIG[gameroot] parameter in multiple PHP scripts.
Description
Multiple PHP remote file inclusion vulnerabilities in Shadows Rising RPG (Pre-Alpha) 0.0.5b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[gameroot] parameter to (1) core/includes/security.inc.php, (2) core/includes/smarty.inc.php, (3) qcms/includes/smarty.inc.php or (4) qlib/smarty.inc.php.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in Shadows Rising RPG (Pre-Alpha) <= 0.0.5b. The vulnerability allows an attacker to include remote files via the CONFIG[gameroot] parameter in multiple PHP scripts.