CVE-2006-5386
NuralStorm Webmail <= 0.98b - Remote File Inclusion via DEFAULT_SKIN Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5386. PoCs published by Kw3[R]Ln.
AI-analyzed exploit summary The exploit describes a remote file inclusion vulnerability in NuralStorm Webmail <= 0.98b due to an unsanitized $DEFAULT_SKIN variable when register_globals is enabled. The attacker can inject a malicious script via the DEFAULT_SKIN parameter in process.php.
Description
PHP remote file inclusion vulnerability in process.php in NuralStorm Webmail 0.98b and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DEFAULT_SKIN parameter.
Exploits (1)
The exploit describes a remote file inclusion vulnerability in NuralStorm Webmail <= 0.98b due to an unsanitized $DEFAULT_SKIN variable when register_globals is enabled. The attacker can inject a malicious script via the DEFAULT_SKIN parameter in process.php.