CVE-2006-5767
Drake CMS < 0.2.2_alpha_r846 - Remote Code Execution via d_root Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5767. PoCs published by GregStar.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Drake CMS v0.2.2 ALPHA rev.846. The vulnerable parameter 'd_root' in 'includes/xhtml.php' allows an attacker to include and execute arbitrary remote files, leading to potential remote code execution.
Description
PHP remote file inclusion vulnerability in includes/xhtml.php in Drake CMS 0.2.2 alpha rev.846 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the d_root parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Drake CMS v0.2.2 ALPHA rev.846. The vulnerable parameter 'd_root' in 'includes/xhtml.php' allows an attacker to include and execute arbitrary remote files, leading to potential remote code execution.