CVE-2006-4750
openi-cms 1.0.1 - Remote File Inclusion via config[openi_dir] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4750. PoCs published by basher13.
AI-analyzed exploit summary The exploit describes a remote file inclusion vulnerability in OPENi-CMS 1.0.1 due to improper validation of the 'config[openi_dir]' parameter in fileloader.php. Attackers can include arbitrary remote files by manipulating the parameter.
Description
PHP remote file inclusion vulnerability in openi-admin/base/fileloader.php in OPENi-CMS 1.0.1, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the config[openi_dir] parameter.
Exploits (1)
The exploit describes a remote file inclusion vulnerability in OPENi-CMS 1.0.1 due to improper validation of the 'config[openi_dir]' parameter in fileloader.php. Attackers can include arbitrary remote files by manipulating the parameter.