CVE-2006-6738
cwmcounter < 5.1.1 - Remote Code Execution via Path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6738. PoCs published by bd0rk.
AI-analyzed exploit summary This exploit targets a remote file inclusion vulnerability in cwmCounter's statistic.php, allowing arbitrary command execution via an external shell. It uses LWP::UserAgent to send crafted HTTP requests with user-supplied commands.
Description
PHP remote file inclusion vulnerability in statistic.php in cwmCounter 5.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
Exploits (1)
This exploit targets a remote file inclusion vulnerability in cwmCounter's statistic.php, allowing arbitrary command execution via an external shell. It uses LWP::UserAgent to send crafted HTTP requests with user-supplied commands.