CVE-2006-5506
WiClear 0.10 - Remote Code Execution via Path Parameter in Multiple PHP Scripts
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5506. PoCs published by the master.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in wiclear v0.10. The attacker can include remote files via the 'path' parameter in multiple PHP scripts, potentially leading to remote code execution.
Description
Multiple PHP remote file inclusion vulnerabilities in WiClear 0.10 allow remote attackers to execute arbitrary PHP code via the path parameter in (1) inc/prepend.inc.php, (2) inc/lib/boxes.lib.php, (3) inc/lib/tools.lib.php, (4) tools/trackback/index.php, and (5) tools/utf8conversion/index.php in admin/; and (6) prepend.inc.php, (7) lib/boxes.lib.php, and (8) lib/history.lib.php in inc/.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in wiclear v0.10. The attacker can include remote files via the 'path' parameter in multiple PHP scripts, potentially leading to remote code execution.