Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-5919. PoCs published by igi.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in KnowledgeBuilder v2.2 PHP NULL-WDYL. The vulnerability arises from insecure inclusion of files via the 'visEdit_root' parameter, allowing remote attackers to execute arbitrary code by injecting malicious URLs.
Description
PHP remote file inclusion vulnerability in admin/e_data/visEdit_control.class.php in ActiveCampaign KnowledgeBuilder 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the visEdit_root parameter, a different vector than CVE-2003-1131.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in KnowledgeBuilder v2.2 PHP NULL-WDYL. The vulnerability arises from insecure inclusion of files via the 'visEdit_root' parameter, allowing remote attackers to execute arbitrary code by injecting malicious URLs.