CVE-2006-5923
GimeScripts Shopping Catalog < 0.9.1 - Remote File Inclusion via Custom Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5923. PoCs published by v1per-haCker.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Shopping Catalog PHP Script. The vulnerability allows an attacker to include arbitrary remote files via the 'custom' parameter in the 'function' module.
Description
PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the custom parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Shopping Catalog PHP Script. The vulnerability allows an attacker to include arbitrary remote files via the 'custom' parameter in the 'function' module.