Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-5415. PoCs published by Nima Salehi.
AI-analyzed exploit summary This Perl script exploits a Remote File Include (RFI) vulnerability in 'news defilante horizontale' <= 4.1.1 by injecting a remote shell script via the 'phpbb_root_path' parameter. It establishes a TCP connection to the target and sends crafted HTTP requests to execute arbitrary commands.
Description
PHP remote file inclusion vulnerability in includes/functions_newshr.php in the News Defilante Horizontale 4.1.1 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
Exploits (1)
This Perl script exploits a Remote File Include (RFI) vulnerability in 'news defilante horizontale' <= 4.1.1 by injecting a remote shell script via the 'phpbb_root_path' parameter. It establishes a TCP connection to the target and sends crafted HTTP requests to execute arbitrary commands.