Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-4629. PoCs published by SHiKaA.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in C-News <= v1.0.1 due to improper input validation in the 'path' parameter of commentaires.php. An attacker can include a remote shell by manipulating the 'path' parameter to point to a malicious URL.
Description
PHP remote file inclusion vulnerability in affichage/commentaires.php in C-News.fr C-News 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in C-News <= v1.0.1 due to improper input validation in the 'path' parameter of commentaires.php. An attacker can include a remote shell by manipulating the 'path' parameter to point to a malicious URL.