CVE-2006-6552
BLOG:CMS <= 4.1.3 - Remote File Inclusion via DIR_ADMIN Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6552. PoCs published by HACKERS PAL.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in BLOG:CMS by manipulating the DIR_ADMIN parameter to include a remote file. The attack leverages improper input validation to execute arbitrary code.
Description
PHP remote file inclusion vulnerability in admin/plugins/NP_UserSharing.php in BLOG:CMS 4.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DIR_ADMIN parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in BLOG:CMS by manipulating the DIR_ADMIN parameter to include a remote file. The attack leverages improper input validation to execute arbitrary code.