CVE-2006-4354
Phome Empire CMS 3.7 - Remote File Inclusion via CheckLevel.php check_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4354. PoCs published by Bob Linuson.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in Empire CMS <=3.7 via the 'check_path' parameter in checklevel.php. The attacker can include a remote shell by manipulating the parameter to point to a malicious file.
Description
PHP remote file inclusion vulnerability in e/class/CheckLevel.php in Phome Empire CMS 3.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the check_path parameter.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in Empire CMS <=3.7 via the 'check_path' parameter in checklevel.php. The attacker can include a remote shell by manipulating the parameter to point to a malicious file.