CVE-2006-4424
phpCOIN 1.2.3 - Remote File Inclusion via _CCFG[_PKG_PATH_INCL] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4424. PoCs published by Timq.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in phpCOIN 1.2.3 due to improper input validation in the `_CCFG[_PKG_PATH_INCL]` parameter. An attacker can inject a malicious remote script URL to achieve remote code execution.
Description
PHP remote file inclusion vulnerability in coin_includes/constants.php in phpCOIN 1.2.3 allows remote attackers to execute arbitrary PHP code via the _CCFG[_PKG_PATH_INCL] parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in phpCOIN 1.2.3 due to improper input validation in the `_CCFG[_PKG_PATH_INCL]` parameter. An attacker can inject a malicious remote script URL to achieve remote code execution.