CVE-2006-4448
interact 2.2 - Remote File Inclusion via CONFIG[BASE_PATH] or CONFIG[LANGUAGE_CPATH] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4448. PoCs published by Kacper.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in Cce-interact <= 2.2.0 due to improper input validation of the CONFIG[BASE_PATH] parameter. The PoC provides URLs to inject malicious scripts via the vulnerable parameters in admin/autoprompter.php and includes/common.inc.php.
Description
Multiple PHP remote file inclusion vulnerabilities in interact 2.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG[BASE_PATH] parameter in (a) admin/autoprompter.php and (b) includes/common.inc.php, and the (2) CONFIG[LANGUAGE_CPATH] parameter in (c) admin/autoprompter.php.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in Cce-interact <= 2.2.0 due to improper input validation of the CONFIG[BASE_PATH] parameter. The PoC provides URLs to inject malicious scripts via the vulnerable parameters in admin/autoprompter.php and includes/common.inc.php.