CVE-2006-5911
Campware Campsite < 2.6.2 - Remote File Inclusion via g_documentRoot Parameter
Title source: llmExploitation Summary
EIP tracks 38 public exploits for CVE-2006-5911. PoCs published by anonymous.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the `g_DocumentRoot` parameter to include a remote shell.
Description
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute arbitrary PHP code via a URL in the g_documentRoot parameter to (1) Alias.php, (2) Article.php, (3) ArticleAttachment.php, (4) ArticleComment.php, (5) ArticleData.php, (6) ArticleImage.php, (7) ArticleIndex.php, (8) ArticlePublish.php, (9) ArticleTopic.php, (10) ArticleType.php, (11) ArticleTypeField.php, (12) Attachment.php, (13) Country.php, (14) DatabaseObject.php, (15) Event.php, (16) IPAccess.php, (17) Image.php, (18) Issue.php, (19) IssuePublish.php, (20) Language.php, (21) Log.php, (22) LoginAttempts.php, (23) Publication.php, (24) Section.php, (25) ShortURL.php, (26) Subscription.php, (27) SubscriptionDefaultTime.php, (28) SubscriptionSection.php, (29) SystemPref.php, (30) Template.php, (31) TimeUnit.php, (32) Topic.php, (33) UrlType.php, (34) User.php, and (35) UserType.php in implementation/management/classes/; (36) configuration.php and (37) db_connect.php in implementation/management/; and (38) LocalizerConfig.php and (39) LocalizerLanguage.php in implementation/management/priv/localizer/.
Exploits (38)
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the `g_DocumentRoot` parameter to include a remote shell.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the `g_DocumentRoot` parameter in `User.php`. The PoC provides a URL example to include a remote shell.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the `g_DocumentRoot` parameter in the `UrlType.php` script.
The provided text describes a remote file inclusion vulnerability in Campsite 2.6.1, allowing remote code execution via the `g_DocumentRoot` parameter. However, it lacks actual exploit code, making it a writeup rather than a working PoC.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the `g_DocumentRoot` parameter in the `TimeUnit.php` file.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the `g_DocumentRoot` parameter in the `Template.php` file.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1 by manipulating the `g_DocumentRoot` parameter to include a remote shell. The attack allows arbitrary code execution in the context of the webserver.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the `g_DocumentRoot` parameter to include a remote shell.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the `g_DocumentRoot` parameter to include a remote shell.
The provided text describes a remote file inclusion vulnerability in Campsite 2.6.1, allowing remote code execution by manipulating the `g_DocumentRoot` parameter. However, no actual exploit code is included, only a reference URL and a brief description.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1 by manipulating the `g_DocumentRoot` parameter in `ShortURL.php` to include and execute arbitrary remote code.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the `g_DocumentRoot` parameter in the `Section.php` file.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the g_DocumentRoot parameter to include a remote shell.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the g_DocumentRoot parameter to include a remote shell.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the `g_DocumentRoot` parameter in the `Log.php` file.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the `g_DocumentRoot` parameter to include a remote shell.
The provided text describes a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code via a crafted URL. However, the example lacks executable exploit code, making it a writeup rather than a working PoC.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the `g_DocumentRoot` parameter in the `Language.php` file.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the g_DocumentRoot parameter to include a remote shell.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the g_DocumentRoot parameter in the Issue.php script.
This exploit leverages a remote file inclusion vulnerability in Campsite 2.6.1 by manipulating the `g_DocumentRoot` parameter in `IPAccess.php` to include and execute arbitrary remote code.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1 by manipulating the `g_DocumentRoot` parameter in `Image.php` to include and execute arbitrary remote files. The attack vector is straightforward, requiring no authentication.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the `g_DocumentRoot` parameter in the `Event.php` file.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the `g_DocumentRoot` parameter to include a remote shell.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the `g_DocumentRoot` parameter to include a remote shell.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1 by manipulating the g_DocumentRoot parameter to include a remote shell. The attack leverages improper input validation to execute arbitrary code.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing remote attackers to execute arbitrary code by manipulating the `g_DocumentRoot` parameter in the `ArticleType.php` script.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the g_DocumentRoot parameter. The PoC provides a URL example to trigger the vulnerability.
This exploit leverages a remote file inclusion vulnerability in Campsite 2.6.1 by manipulating the `g_DocumentRoot` parameter to include and execute arbitrary remote code. The attack is straightforward and requires no authentication.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1 by manipulating the `g_DocumentRoot` parameter to include a remote shell. The vulnerability allows arbitrary code execution in the context of the webserver.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the `g_DocumentRoot` parameter in `ArticleImage.php`. The PoC provides a URL example to include a remote shell.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the `g_DocumentRoot` parameter to include a remote shell.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the `g_DocumentRoot` parameter to include a remote shell.
The exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1 by manipulating the `g_DocumentRoot` parameter to include and execute arbitrary remote files. This leads to remote code execution in the context of the webserver.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1 by manipulating the `g_DocumentRoot` parameter to include a remote shell. The attack relies on improper input validation to execute arbitrary code.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the `g_DocumentRoot` parameter in the `Alias.php` file. The PoC provides a URL example to include a remote shell file.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the `g_DocumentRoot` parameter in `db_connect.php`. The PoC provides a URL example to include a remote shell file.
This exploit demonstrates a remote file inclusion vulnerability in Campsite 2.6.1, allowing attackers to execute arbitrary code by manipulating the g_DocumentRoot parameter in configuration.php. The PoC provides a URL example to include a remote shell file.