CVE-2006-5181
phpMyWebmin 1.0 - Remote File Inclusion via Target Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5181. PoCs published by Mehmet Ince.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in phpMyWebmin 1.0, allowing an attacker to include arbitrary remote files via the 'target' parameter in multiple scripts. The vulnerability arises from unsanitized user input in the include statement.
Description
Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the target parameter in (1) change_preferences2.php, (2) create_file.php, (3) upload_local.php, and (4) upload_multi.php, different vectors than CVE-2006-5124.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in phpMyWebmin 1.0, allowing an attacker to include arbitrary remote files via the 'target' parameter in multiple scripts. The vulnerability arises from unsanitized user input in the include statement.