CVE-2006-4720
mcgallery_pro 2006 - Remote File Inclusion via random2.php path_to_folder Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4720. PoCs published by Solpot.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Mcgallerypro due to improper verification of the 'path_to_folder' parameter. An attacker can include arbitrary PHP files from local or external resources, leading to remote code execution.
Description
PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in Mcgallerypro due to improper verification of the 'path_to_folder' parameter. An attacker can include arbitrary PHP files from local or external resources, leading to remote code execution.