CVE-2006-7091
phpht Topsites FREE 1.022b - Remote File Inclusion via config.php fullpath Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-7091. PoCs published by Le CoPrA.
AI-analyzed exploit summary The code describes a remote file-include vulnerability in PHP TopSites 1.022 due to insufficient input sanitization. An attacker can exploit this by manipulating the 'fullpath' parameter in config.php to execute arbitrary PHP code.
Description
PHP remote file inclusion vulnerability in config.php in phpht Topsites FREE 1.022b allows remote attackers to execute arbitrary PHP code via a URL in the fullpath parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
The code describes a remote file-include vulnerability in PHP TopSites 1.022 due to insufficient input sanitization. An attacker can exploit this by manipulating the 'fullpath' parameter in config.php to execute arbitrary PHP code.