CVE-2006-6232
DreamAccount 3.1 - Remote File Inclusion via Admin Index Path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6232. PoCs published by CrAsh_oVeR_rIdE.
AI-analyzed exploit summary This exploit targets a file inclusion vulnerability in DreamAccount V3.1's auth.api.php, allowing remote command execution via a malicious path parameter. It uses HTTP requests to inject and execute arbitrary commands through an external PHP script.
Description
PHP remote file inclusion vulnerability in admin/index.php in DreamAccount 3.1 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
Exploits (1)
This exploit targets a file inclusion vulnerability in DreamAccount V3.1's auth.api.php, allowing remote command execution via a malicious path parameter. It uses HTTP requests to inject and execute arbitrary commands through an external PHP script.