CVE-2006-4828
PhotoPost PHP Pro 4.0-4.6 - Remote File Inclusion via PP_PATH Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4828. PoCs published by Saudi Hackrz.
AI-analyzed exploit summary This exploit targets a remote file inclusion vulnerability in PhotoPost versions 4.6 and earlier. The vulnerability exists in the `zipndownload.php` file due to improper sanitization of the `PP_PATH` parameter, allowing an attacker to include arbitrary remote files.
Description
PHP remote file inclusion vulnerability in zipndownload.php in PhotoPost 4.0 through 4.6 allows remote attackers to execute arbitrary PHP code via a URL in the PP_PATH parameter.
Exploits (1)
This exploit targets a remote file inclusion vulnerability in PhotoPost versions 4.6 and earlier. The vulnerability exists in the `zipndownload.php` file due to improper sanitization of the `PP_PATH` parameter, allowing an attacker to include arbitrary remote files.