CVE-2006-5863
otterware letterit2 - Remote File Inclusion via lang Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2006-5863. PoCs published by Security Access Point, v1per-haCker.
AI-analyzed exploit summary This exploit demonstrates SQL injection and authentication bypass vulnerabilities in HP eCS Shopping Cart. It provides specific payloads for bypassing login and injecting SQL queries via the search functionality.
Description
PHP remote file inclusion vulnerability in inc/session.php for LetterIt 2 allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter.
Exploits (2)
This exploit demonstrates SQL injection and authentication bypass vulnerabilities in HP eCS Shopping Cart. It provides specific payloads for bypassing login and injecting SQL queries via the search functionality.
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in LetterIt version 2. The vulnerability allows an attacker to include arbitrary remote files via the 'lang' parameter in the 'session.php' script.