CVE-2006-6462
CM68 News 12.02.06 - Remote Code Execution via addpath Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6462. PoCs published by Paul Bakoyiannis.
AI-analyzed exploit summary The exploit demonstrates a file inclusion vulnerability in cm68news via the 'addpath' parameter in /engine/oldnews.inc.php. By manipulating the parameter, an attacker can include remote files, leading to potential remote code execution.
Description
PHP remote file inclusion vulnerability in engine/oldnews.inc.php in CM68 News 12.02.06 allows remote attackers to execute arbitrary PHP code via a URL in the addpath parameter.
Exploits (1)
The exploit demonstrates a file inclusion vulnerability in cm68news via the 'addpath' parameter in /engine/oldnews.inc.php. By manipulating the parameter, an attacker can include remote files, leading to potential remote code execution.