CVE-2006-4987
Patrick Michaelis Wili-CMS - Remote File Inclusion via globals[content_dir] Parameter
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4987.
AI-analyzed exploit summary The exploit demonstrates multiple input validation vulnerabilities in Wili-CMS, including remote file inclusion (RFI), cross-site scripting (XSS), and full path disclosure. The RFI vectors allow remote code execution by including arbitrary files via the `globals[content_dir]` parameter, while XSS vectors exploit unsanitized input in various scripts.
Description
Multiple PHP remote file inclusion vulnerabilities in Patrick Michaelis Wili-CMS allow remote attackers to execute arbitrary PHP code via a URL in the globals[content_dir] parameter in (1) example-view/templates/article.php, (2) example-view/templates/root.php, and (3) example-view/templates/dates_list.php.
Exploits (1)
The exploit demonstrates multiple input validation vulnerabilities in Wili-CMS, including remote file inclusion (RFI), cross-site scripting (XSS), and full path disclosure. The RFI vectors allow remote code execution by including arbitrary files via the `globals[content_dir]` parameter, while XSS vectors exploit unsanitized input in various scripts.