CVE-2006-5280
Leicestershire communityPortals < 1.build_20051018 - Remote Code Execution via cp_root_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5280. PoCs published by Nima Salehi.
AI-analyzed exploit summary This exploit targets a remote file include vulnerability in CommunityPortals <= 1.0 by injecting a remote shell script via the 'cp_root_path' parameter. It allows arbitrary command execution by fetching and executing commands from an attacker-controlled server.
Description
PHP remote file inclusion vulnerability in includes/import-archive.php in Leicestershire communityPortals 1.0 build 20051018 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter.
Exploits (1)
This exploit targets a remote file include vulnerability in CommunityPortals <= 1.0 by injecting a remote shell script via the 'cp_root_path' parameter. It allows arbitrary command execution by fetching and executing commands from an attacker-controlled server.