Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-6856. PoCs published by Kacper.
AI-analyzed exploit summary This exploit targets a remote code execution vulnerability in WebText <= 0.4.5.2 by injecting malicious PHP code into the user profile's 'imie' field. The exploit registers a new user, edits the profile to include the payload, and then triggers the payload by accessing the user's profile file.
Description
Direct static code injection vulnerability in WebText CMS 0.4.5.2 and earlier allows remote attackers to inject arbitrary PHP code into a script in wt/users/ via the im parameter during a profile edit (edycja) operation, which is then executed via a direct request for this script.
Exploits (1)
This exploit targets a remote code execution vulnerability in WebText <= 0.4.5.2 by injecting malicious PHP code into the user profile's 'imie' field. The exploit registers a new user, edits the profile to include the payload, and then triggers the payload by accessing the user's profile file.