CVE-2006-7169
Ultimate PHP Board < 2.0 - Remote File Inclusion via _CONFIG[skin_dir] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-7169. PoCs published by Kacper.
AI-analyzed exploit summary This exploit targets a file inclusion vulnerability in Ultimate PHP Board <= 2.0 by injecting a remote shell via the `_CONFIG[skin_dir]` parameter. It sends a crafted HTTP GET request to execute arbitrary commands on the server.
Description
PHP remote file inclusion vulnerability in includes/header_simple.php in Ultimate PHP Board (UPB) 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _CONFIG[skin_dir] parameter.
Exploits (1)
This exploit targets a file inclusion vulnerability in Ultimate PHP Board <= 2.0 by injecting a remote shell via the `_CONFIG[skin_dir]` parameter. It sends a crafted HTTP GET request to execute arbitrary commands on the server.