CVE-2006-4849
MobilePublisherPHP < 1.5_rc2 - Remote File Inclusion via abspath Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4849. PoCs published by Timq.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in MobilePublisherPHP 1.5 RC2 due to improper input validation in the 'abspath' parameter. An attacker can include a remote PHP shell to achieve remote code execution.
Description
PHP remote file inclusion vulnerability in header.php in MobilePublisherPHP 1.5 RC2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in MobilePublisherPHP 1.5 RC2 due to improper input validation in the 'abspath' parameter. An attacker can include a remote PHP shell to achieve remote code execution.