CVE-2006-5834
OpenSolution Quick.Cms.Lite 0.3 - Directory Traversal via sLanguage Cookie Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5834. PoCs published by Kacper.
AI-analyzed exploit summary This exploit leverages a local file inclusion vulnerability in Quick.Cms.Lite <= 0.3 by manipulating the `sLanguage` cookie to include arbitrary log files containing malicious PHP code. The exploit injects base64-encoded PHP code into server logs and then triggers its execution via the vulnerable cookie parameter.
Description
Directory traversal vulnerability in general.php in OpenSolution Quick.Cms.Lite 0.3 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the sLanguage Cookie parameter.
Exploits (1)
This exploit leverages a local file inclusion vulnerability in Quick.Cms.Lite <= 0.3 by manipulating the `sLanguage` cookie to include arbitrary log files containing malicious PHP code. The exploit injects base64-encoded PHP code into server logs and then triggers its execution via the vulnerable cookie parameter.