CVE-2006-4946
CMSDevelopment Business Card Web Builder < 2.5 - Remote File Inclusion via root_path Parameter
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4946. PoCs published by ajann.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Bcwb 0.99 by manipulating the 'root_path' parameter to include arbitrary remote files. The PoC shows how an attacker can inject a malicious PHP file via the 'root_path' parameter.
Description
PHP remote file inclusion vulnerability in include/startup.inc.php in CMSDevelopment Business Card Web Builder (BCWB) 0.99, and possibly 2.5 Beta and earlier, allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in Bcwb 0.99 by manipulating the 'root_path' parameter to include arbitrary remote files. The PoC shows how an attacker can inject a malicious PHP file via the 'root_path' parameter.