CVE-2006-4649
BinGo News < 3.01 - Remote Code Execution via bnrep Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4649. PoCs published by SHiKaA.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in BinGo News <= v3.01 due to improper input validation in the 'bnrep' parameter in bp_ncom.php. An attacker can include a remote shell by manipulating the parameter to point to a malicious URL.
Description
PHP remote file inclusion vulnerability in bp_news.php in BinGo News (BP News) 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the bnrep parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in BinGo News <= v3.01 due to improper input validation in the 'bnrep' parameter in bp_ncom.php. An attacker can include a remote shell by manipulating the parameter to point to a malicious URL.