CVE-2006-7069
Socketwiz Bookmarks < 2.0 - Remote File Inclusion via smarty_config.php root_dir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-7069. PoCs published by Kacper.
AI-analyzed exploit summary This Perl script exploits a Remote File Include (RFI) vulnerability in Socketwiz Bookmarks <= 2.0 by injecting a malicious URL into the 'root_dir' parameter of 'smarty_config.php'. It allows remote command execution via a user-provided shell script.
Description
PHP remote file inclusion vulnerability in smarty_config.php in Socketwiz Bookmarks 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the root_dir parameter.
Exploits (1)
This Perl script exploits a Remote File Include (RFI) vulnerability in Socketwiz Bookmarks <= 2.0 by injecting a malicious URL into the 'root_dir' parameter of 'smarty_config.php'. It allows remote command execution via a user-provided shell script.