CVE-2006-4670
PhotoKorn Gallery < 1.52 - Remote File Inclusion via dir_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4670. PoCs published by Saudi Hackrz.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in PhotoKorn Gallery v1.52. The vulnerability allows an attacker to include arbitrary remote files via the 'dir_path' parameter in cart.inc.php and ext_cats.php.
Description
Multiple PHP remote file inclusion vulnerabilities in PhotoKorn Gallery 1.52 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter in (1) includes/cart.inc.php or (2) extras/ext_cats.php.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in PhotoKorn Gallery v1.52. The vulnerability allows an attacker to include arbitrary remote files via the 'dir_path' parameter in cart.inc.php and ext_cats.php.