Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-4636. PoCs published by Kacper.
AI-analyzed exploit summary This exploit targets a file upload vulnerability in PhpCommander <= 3.0, allowing remote code execution by uploading a malicious PHP shell disguised as a JPEG file and then executing arbitrary commands via a crafted GET request.
Description
Directory traversal vulnerability in SZEWO PhpCommander 3.0 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Directory parameter, as demonstrated by parameter values naming Apache HTTP Server log files that apparently contain PHP code.
Exploits (1)
This exploit targets a file upload vulnerability in PhpCommander <= 3.0, allowing remote code execution by uploading a malicious PHP shell disguised as a JPEG file and then executing arbitrary commands via a crafted GET request.