CVE-2006-7146
Leicestershire communityPortals < 1.0 - Remote Code Execution via cp_root_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-7146. PoCs published by Nima Salehi.
AI-analyzed exploit summary This exploit targets a remote file include vulnerability in CommunityPortals 1.0 Build 12-31-18 by injecting a malicious URL into the 'cp_root_path' parameter, allowing arbitrary command execution via a remote shell script.
Description
PHP remote file inclusion vulnerability in bug.php in Leicestershire communityPortals 1.0 build 20051018 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter, a different vector than CVE-2006-5280. NOTE: CVE disputes this issue, since bug.php is not in communityPortals source distributions
Exploits (1)
This exploit targets a remote file include vulnerability in CommunityPortals 1.0 Build 12-31-18 by injecting a malicious URL into the 'cp_root_path' parameter, allowing arbitrary command execution via a remote shell script.