CVE-2006-4827
vmist/downstat < 1.8 - Remote File Inclusion via Art Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4827. PoCs published by SilenZ.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in downstat 1.8, where the 'art' parameter in multiple PHP scripts is not sanitized, allowing an attacker to include arbitrary remote files. The vulnerability can lead to remote code execution if the attacker hosts malicious PHP code.
Description
Multiple PHP remote file inclusion vulnerabilities in Vmist Downstat 1.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the art parameter to (1) admin.php, (2) chart.php, (3) modes.php, or (4) stats.php.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in downstat 1.8, where the 'art' parameter in multiple PHP scripts is not sanitized, allowing an attacker to include arbitrary remote files. The vulnerability can lead to remote code execution if the attacker hosts malicious PHP code.