Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-5254. PoCs published by k1tk4t.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Mambo's com_registration_detailed component (version <= 4.1). The vulnerability arises from improper input validation in the 'mosConfig_absolute_path' parameter, allowing an attacker to include arbitrary remote files.
Description
PHP remote file inclusion vulnerability in registration_detailed.inc.php in Mark Van Bellen Detailed User Registration (com_registration_detailed), aka regdetailed, 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Mambo's com_registration_detailed component (version <= 4.1). The vulnerability arises from improper input validation in the 'mosConfig_absolute_path' parameter, allowing an attacker to include arbitrary remote files.