CVE-2006-5429
BRIM < 1.2.1 - Remote File Inclusion via Renderer Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5429. PoCs published by mdx.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Brim 1.2.0pre3 and 1.2.1, allowing an attacker to include arbitrary remote files via the 'renderer' parameter in multiple template files.
Description
Multiple PHP remote file inclusion vulnerabilities in Barry Nauta BRIM 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the renderer parameter in template.tpl.php in (1) templates/barrel/, (2) templates/sidebar/, (3) templates/text-only, (4) templates/slashdot/, (5) templates/penguin/, (6) templates/pda/, (7) templates/oerdec/, (8) templates/nifty/, (9) templates/mylook, and (10) templates/barry/.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in Brim 1.2.0pre3 and 1.2.1, allowing an attacker to include arbitrary remote files via the 'renderer' parameter in multiple template files.