CVE-2006-5522
Johannes Erdfelt Kawf < 1.0 - Remote File Inclusion via Config Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5522. PoCs published by o0xxdark0o.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion (RFI) vulnerability in Kawf web forum v1.0 and below. The vulnerability allows an attacker to include arbitrary remote files via the 'config' parameter in main.php, leading to potential remote code execution.
Description
Multiple PHP remote file inclusion vulnerabilities in Johannes Erdfelt Kawf 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the config parameter in (1) main.php or (2) user/account/main.php.
Exploits (1)
This exploit demonstrates a remote file inclusion (RFI) vulnerability in Kawf web forum v1.0 and below. The vulnerability allows an attacker to include arbitrary remote files via the 'config' parameter in main.php, leading to potential remote code execution.