CVE-2006-5061
Advanced-Clan-Script < 3.4 - Remote File Inclusion via mcf.php content Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5061. PoCs published by xdh.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in AdVancedClanscript versions prior to 3.4. The vulnerability is located in the 'mcf.php' file, where the 'content' parameter is directly included without proper sanitization, allowing an attacker to include arbitrary remote files.
Description
PHP remote file inclusion vulnerability in mcf.php in Advanced-Clan-Script (AVCX) 3.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in AdVancedClanscript versions prior to 3.4. The vulnerability is located in the 'mcf.php' file, where the 'content' parameter is directly included without proper sanitization, allowing an attacker to include arbitrary remote files.