CVE-2006-5480
Castor PHP Web Builder 1.1.1 - Remote Code Execution via rootpath Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5480. PoCs published by Kw3[R]Ln.
AI-analyzed exploit summary This exploit targets a remote command execution vulnerability in CASTOR <= 1.1.1 by injecting a malicious script via the 'rootpath' parameter in rs.php. It uses LWP::Simple to send HTTP requests and execute arbitrary commands on the target system.
Description
PHP remote file inclusion vulnerability in lib/rs.php in 2le.net Castor PHP Web Builder 1.1.1 allows remote attackers to execute arbitrary PHP code via the rootpath parameter.
Exploits (1)
This exploit targets a remote command execution vulnerability in CASTOR <= 1.1.1 by injecting a malicious script via the 'rootpath' parameter in rs.php. It uses LWP::Simple to send HTTP requests and execute arbitrary commands on the target system.