Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-5022. PoCs published by CvIr.System.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in PowerNews v1.1.0. The vulnerable code in 'includes/global.php' allows an attacker to include arbitrary remote files by manipulating the 'nbs' parameter.
Description
PHP remote file inclusion vulnerability in includes/global.php in Joshua Wilson pNews System 1.1.0 (aka PowerNews) allows remote attackers to execute arbitrary PHP code via a URL in the nbs parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in PowerNews v1.1.0. The vulnerable code in 'includes/global.php' allows an attacker to include arbitrary remote files by manipulating the 'nbs' parameter.