CVE-2006-4488
ExBB Italia < 0.2 - Remote File Inclusion via exbb[home_path] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4488. PoCs published by SHiKaA.
AI-analyzed exploit summary This exploit targets a remote file inclusion vulnerability in ExBB Italian version <= 2.0. The vulnerability exists in the 'userstop.php' script due to improper input validation of the 'exbb[home_path]' parameter, allowing an attacker to include arbitrary remote files.
Description
PHP remote file inclusion vulnerability in modules/userstop/userstop.php in ExBB Italia 0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the exbb[home_path] parameter.
Exploits (1)
This exploit targets a remote file inclusion vulnerability in ExBB Italian version <= 2.0. The vulnerability exists in the 'userstop.php' script due to improper input validation of the 'exbb[home_path]' parameter, allowing an attacker to include arbitrary remote files.