CVE-2006-4890
UNAK-CMS <= 1.5 - Remote File Inclusion via dirroot Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4890. PoCs published by SHiKaA.
AI-analyzed exploit summary This exploit targets a Remote File Inclusion (RFI) vulnerability in UNAK-CMS <= v1.5 via the 'dirroot' parameter in 'fck_link.php'. The PoC demonstrates how an attacker can include a remote shell by manipulating the 'dirroot' parameter to execute arbitrary commands.
Description
Multiple PHP remote file inclusion vulnerabilities in UNAK-CMS 1.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the dirroot parameter to (1) fckeditor/editor/filemanager/browser/default/connectors/php/connector.php or (2) fckeditor/editor/dialog/fck_link.php.
Exploits (1)
This exploit targets a Remote File Inclusion (RFI) vulnerability in UNAK-CMS <= v1.5 via the 'dirroot' parameter in 'fck_link.php'. The PoC demonstrates how an attacker can include a remote shell by manipulating the 'dirroot' parameter to execute arbitrary commands.