Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-6809. PoCs published by DeltahackingTEAM.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Bubla <= 1.0.0rc2, allowing remote code execution by manipulating the 'bu_dir' or 'bu_config[dir]' parameter in process.php to include a malicious remote file.
Description
Multiple PHP remote file inclusion vulnerabilities in process.php in Vladimir Menshakov buratinable templator (aka bubla) 1.0.0rc2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) bu_dir or (2) bu_config[dir] parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Bubla <= 1.0.0rc2, allowing remote code execution by manipulating the 'bu_dir' or 'bu_config[dir]' parameter in process.php to include a malicious remote file.