CVE-2006-5234
phpWebSite 0.10.2 - Remote File Inclusion via PHPWS_SOURCE_DIR Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5234. PoCs published by Crackers_Child.
AI-analyzed exploit summary The provided text describes a retired remote file-include vulnerability in phpWebSite 0.10.2, where the 'PHPWS_SOURCE_DIR' parameter was initially thought to be exploitable but was later determined to be a constant, not attacker-controlled. The URLs listed are examples of attempted exploitation paths, but the vulnerability is not actionable as described.
Description
Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPWS_SOURCE_DIR parameter in (1) init.php, (2) users.php, (3) Cookie.php, (4) forms.php, (5) Groups.php, (6) ModSetting.php, (7) Calendar.php, (8) DateTime.php, (9) core.php, (10) ImgLibrary.php, (11) Manager.php, and (12) Template.php, and (13) EZform.php. NOTE: CVE disputes this report, since "PHPWS_SOURCE_DIR" is defined as a constant, not accessed as a variable
Exploits (1)
The provided text describes a retired remote file-include vulnerability in phpWebSite 0.10.2, where the 'PHPWS_SOURCE_DIR' parameter was initially thought to be exploitable but was later determined to be a constant, not attacker-controlled. The URLs listed are examples of attempted exploitation paths, but the vulnerability is not actionable as described.