CVE-2006-4993
AllMyGuests < 0.4.1 - Remote File Inclusion via _AMGconfig[cfg_serverpath] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4993. PoCs published by Br@Him.
AI-analyzed exploit summary This is a writeup describing a Remote File Inclusion (RFI) vulnerability in AllMyGuests. It provides exploit URLs and search queries to identify vulnerable targets but does not include functional exploit code.
Description
Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.4.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _AMGconfig[cfg_serverpath] parameter in (1) modules/AllMyGuests/signin.php (aka the Nuke module) and (2) AllMyGuests/signin.php (aka the standalone).
Exploits (1)
This is a writeup describing a Remote File Inclusion (RFI) vulnerability in AllMyGuests. It provides exploit URLs and search queries to identify vulnerable targets but does not include functional exploit code.