CVE-2006-4363
CropImage component 1.0 for Mambo - Remote File Inclusion via cropimagedir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4363. PoCs published by Mehmet Ince.
AI-analyzed exploit summary This is a writeup describing a remote file inclusion vulnerability in Mambo com_cropimage 1.0. The exploit leverages an unsafe `require_once` call in `admin.cropcanvas.php` to include arbitrary remote files.
Description
PHP remote file inclusion vulnerability in admin.cropcanvas.php in the CropImage component (com_cropimage) 1.0 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the cropimagedir parameter.
Exploits (1)
This is a writeup describing a remote file inclusion vulnerability in Mambo com_cropimage 1.0. The exploit leverages an unsafe `require_once` call in `admin.cropcanvas.php` to include arbitrary remote files.