CVE-2006-5672
MySource CMS < 2.16.2 - Remote File Inclusion via INCLUDE_PATH Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5672. PoCs published by Kacper.
AI-analyzed exploit summary This exploit targets a remote file inclusion vulnerability in MySource CMS <= 2.16.2 via the 'INCLUDE_PATH' parameter in 'init_mysource.php'. It allows remote command execution by including a malicious shell script and passing commands via the 'cmd' parameter.
Description
PHP remote file inclusion vulnerability in web/init_mysource.php in MySource CMS 2.16.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter.
Exploits (1)
This exploit targets a remote file inclusion vulnerability in MySource CMS <= 2.16.2 via the 'INCLUDE_PATH' parameter in 'init_mysource.php'. It allows remote command execution by including a malicious shell script and passing commands via the 'cmd' parameter.