CVE-2006-5623
ee_tool < 0.4_1 - Remote File Inclusion via cgipath Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5623. PoCs published by Mehmet Ince.
AI-analyzed exploit summary This exploit leverages a file inclusion vulnerability in the 'ip.inc.php' script by manipulating the 'type' and 'cgipath' parameters to include arbitrary remote scripts. The vulnerability allows remote code execution (RCE) by including malicious scripts hosted on an attacker-controlled server.
Description
PHP remote file inclusion vulnerability in ip.inc.php in Electronic Engineering Tool (EE Tool) 0.4-1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cgipath parameter.
Exploits (1)
This exploit leverages a file inclusion vulnerability in the 'ip.inc.php' script by manipulating the 'type' and 'cgipath' parameters to include arbitrary remote scripts. The vulnerability allows remote code execution (RCE) by including malicious scripts hosted on an attacker-controlled server.