CVE-2006-5434
P-News 1.16-1.17 - Remote File Inclusion via pn_lang Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5434. PoCs published by vegas78.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in P-News 1.16 and 1.17 due to improper path handling in PHP include statements. An attacker can inject a remote shell by manipulating the 'pn_lang' parameter.
Description
PHP remote file inclusion vulnerability in p-news.php in P-News 1.16 and 1.17 allows remote attackers to execute arbitrary PHP code via a URL in the pn_lang parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in P-News 1.16 and 1.17 due to improper path handling in PHP include statements. An attacker can inject a remote shell by manipulating the 'pn_lang' parameter.