Exploitation Summary
EIP tracks 2 public exploits for CVE-2006-5068. PoCs published by SHiKaA.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in BrudaNews <= v1.1 due to improper input validation in the 'o' parameter of admin/index.php. An attacker can include and execute arbitrary remote PHP files by manipulating the 'o' parameter.
Description
PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the o parameter.
Exploits (2)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in BrudaNews <= v1.1 due to improper input validation in the 'o' parameter of admin/index.php. An attacker can include and execute arbitrary remote PHP files by manipulating the 'o' parameter.
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in BrudaGB v1.1 and v1.0. The vulnerability exists in the 'admin/index.php' file due to improper handling of the 'o' parameter, allowing remote inclusion of arbitrary PHP files.