CVE-2006-6631
osprey < 1.0 - Remote File Inclusion via lib_dir Parameter
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6631. PoCs published by Kw3[R]Ln.
AI-analyzed exploit summary The exploit describes a remote file inclusion vulnerability in Osprey <= 1.0 due to unsanitized $lib_dir variable when register_globals is enabled. It provides a URL-based proof-of-concept for remote code execution via PHP injection.
Description
PHP remote file inclusion vulnerability in lib/xml/oai/GetRecord.php in osprey 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_dir parameter.
Exploits (1)
The exploit describes a remote file inclusion vulnerability in Osprey <= 1.0 due to unsanitized $lib_dir variable when register_globals is enabled. It provides a URL-based proof-of-concept for remote code execution via PHP injection.