CVE-2006-4437
Tagger LE - Remote Code Execution via Query String Eval Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4437. PoCs published by Morgan.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Tagger v3 due to improper input validation in the 'BBCodeFile' parameter in tags.php. An attacker can include a remote file containing malicious code, leading to remote code execution.
Description
Eval injection vulnerability in Tagger LE allows remote attackers to execute arbitrary PHP code via the query string in (1) tags.php, (2) sign.php, and (3) admin/index.php.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in Tagger v3 due to improper input validation in the 'BBCodeFile' parameter in tags.php. An attacker can include a remote file containing malicious code, leading to remote code execution.