CVE-2006-5401
AROUNDMe < 0.5.2 - Remote File Inclusion via templatePath Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5401. PoCs published by Kw3[R]Ln.
AI-analyzed exploit summary The exploit describes a remote file inclusion vulnerability in AROUNDMe <= 0.5.2 due to unsanitized $templatePath variable when register_globals is enabled. It provides a URL-based PoC but lacks executable code.
Description
PHP remote file inclusion vulnerability in template/barnraiser_01/p_new_password.tpl.php in AROUNDMe 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the templatePath parameter.
Exploits (1)
The exploit describes a remote file inclusion vulnerability in AROUNDMe <= 0.5.2 due to unsanitized $templatePath variable when register_globals is enabled. It provides a URL-based PoC but lacks executable code.