CVE-2006-7102
phpburningportal_quiz-modul < 1.0.1 - Remote Code Execution via lang_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-7102. PoCs published by r0ut3r.
AI-analyzed exploit summary This exploit targets a Remote File Include (RFI) vulnerability in phpBurningPortal's quiz module (version 1.0.1). It allows an attacker to include and execute arbitrary remote shell scripts via manipulated 'lang_path' parameters in multiple PHP files.
Description
Multiple PHP remote file inclusion vulnerabilities in phpBurningPortal quiz-modul 1.0.1, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the lang_path parameter to (1) quest_delete.php, (2) quest_edit.php, or (3) quest_news.php.
Exploits (1)
This exploit targets a Remote File Include (RFI) vulnerability in phpBurningPortal's quiz module (version 1.0.1). It allows an attacker to include and execute arbitrary remote shell scripts via manipulated 'lang_path' parameters in multiple PHP files.