Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-4918. PoCs published by CeNGiZ-HaN.
AI-analyzed exploit summary This exploit demonstrates a file inclusion vulnerability in Simple Discussion Board (sdb) version 0.1.0. The vulnerability allows remote attackers to include arbitrary files by manipulating the 'env_dir' or 'script_root' parameters in multiple scripts.
Description
Multiple PHP remote file inclusion vulnerabilities in Simple Discussion Board 0.1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) env_dir parameter to (a) blank.php, (b) admin.php, or (c) builddb.php, and the (2) script_root parameter to blank.php.
Exploits (1)
This exploit demonstrates a file inclusion vulnerability in Simple Discussion Board (sdb) version 0.1.0. The vulnerability allows remote attackers to include arbitrary files by manipulating the 'env_dir' or 'script_root' parameters in multiple scripts.