CVE-2006-5495
Trawler Web CMS < 1.8.1 - Remote File Inclusion via Multiple PHP Script Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5495. PoCs published by k1tk4t.
AI-analyzed exploit summary This is a writeup detailing multiple remote file inclusion (RFI) vulnerabilities in Trawler CMS version 1.8.1. It lists several endpoints where the 'path_red2' or similar parameters can be manipulated to include remote files, potentially leading to arbitrary code execution.
Description
Multiple PHP remote file inclusion vulnerabilities in Trawler Web CMS 1.8.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) path_red2 parameter to (a) _msdazu_pdata/redaktion/artikel/up/index.php; (b) addtort.php, (c) colorpik2.php, (d) colorpik3.php, (e) extras_menu.php, (f) farbpalette.php, (g) lese_inc.php, and (h) newfile.php in _msdazu_share/richtext/; the (2) path_scr_dat2 parameter to (i)_msdazu_share/share/insert1.php; the (3) path_red parameter to (j) _msdazu_share/extras/downloads/index.php; and unspecified parameters in other files.
Exploits (1)
This is a writeup detailing multiple remote file inclusion (RFI) vulnerabilities in Trawler CMS version 1.8.1. It lists several endpoints where the 'path_red2' or similar parameters can be manipulated to include remote files, potentially leading to arbitrary code execution.