CVE-2006-5310
Les Visiteurs 2.0.1 - Remote Code Execution via lvc_include_dir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5310. PoCs published by k1tk4t.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in phpMyConferences <= 8.0.2. The vulnerability arises from insecure inclusion of files via the `lvc_include_dir` parameter, allowing an attacker to include arbitrary remote files.
Description
PHP remote file inclusion vulnerability in common/visiteurs/include/menus.inc.php in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in phpMyConferences <= 8.0.2. The vulnerability arises from insecure inclusion of files via the `lvc_include_dir` parameter, allowing an attacker to include arbitrary remote files.