CVE-2006-5427
Php AMX 0.9.0 - Remote File Inclusion via plug_path Parameter
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5427. PoCs published by MP.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in phpamx 0.90 due to improper input validation in the 'plug_path' parameter. It allows remote code execution by including arbitrary files from an attacker-controlled server.
Description
PHP remote file inclusion vulnerability in plugins/main.php in Php AMX 0.9.0, when register_globals is enabled or magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the plug_path parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in phpamx 0.90 due to improper input validation in the 'plug_path' parameter. It allows remote code execution by including arbitrary files from an attacker-controlled server.