CVE-2006-4741
IDevSpot PhpLinkExchange 1.0 - Remote File Inclusion via svr_rootPhpStart Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4741.
AI-analyzed exploit summary The exploit demonstrates a remote file inclusion (RFI) vulnerability in PhpLinkExchange by manipulating the 'svr_rootPhpStart' parameter to include arbitrary shell files. It also highlights an XSS vulnerability via the 'msg' parameter in user_add.php.
Description
PHP remote file inclusion vulnerability in bits_listings.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to execute arbitrary code via the svr_rootPhpStart parameter.
Exploits (1)
The exploit demonstrates a remote file inclusion (RFI) vulnerability in PhpLinkExchange by manipulating the 'svr_rootPhpStart' parameter to include arbitrary shell files. It also highlights an XSS vulnerability via the 'msg' parameter in user_add.php.