CVE-2006-7091

phpht Topsites FREE 1.022b - Remote File Inclusion via config.php fullpath Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-7091. PoCs published by Le CoPrA.

AI-analyzed exploit summary The code describes a remote file-include vulnerability in PHP TopSites 1.022 due to insufficient input sanitization. An attacker can exploit this by manipulating the 'fullpath' parameter in config.php to execute arbitrary PHP code.

Description

PHP remote file inclusion vulnerability in config.php in phpht Topsites FREE 1.022b allows remote attackers to execute arbitrary PHP code via a URL in the fullpath parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Le CoPrA · textwebappsphp
https://www.exploit-db.com/exploits/28791

The code describes a remote file-include vulnerability in PHP TopSites 1.022 due to insufficient input sanitization. An attacker can exploit this by manipulating the 'fullpath' parameter in config.php to execute arbitrary PHP code.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: PHP TopSites 1.022
No auth needed
Prerequisites: Access to the target web application · PHP TopSites 1.022 installed
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20486

Scores

EPSS 0.0211
EPSS Percentile 79.8%

Details

Status published
Products (1)
hinton_design/phpht_topsites_free 1.022b
Published Mar 02, 2007
Tracked Since Feb 18, 2026