CVE-2006-6212
Site News 2.00 - Remote Code Execution via centre.php page Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6212. PoCs published by DaDIsS.
AI-analyzed exploit summary This is a writeup describing a Remote File Inclusion (RFI) vulnerability in Site News software. The exploit explanation details how the 'centre.php' file unsafely includes a user-controlled parameter without proper validation.
Description
PHP remote file inclusion vulnerability in centre.php in Site News (site_news) 2.00, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This is a writeup describing a Remote File Inclusion (RFI) vulnerability in Site News software. The exploit explanation details how the 'centre.php' file unsafely includes a user-controlled parameter without proper validation.