Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-7173. PoCs published by rgod.
AI-analyzed exploit summary This exploit leverages a vulnerability in Php-Stats <= 0.1.9.1b to inject PHP code via the `report_w_day` parameter, then executes arbitrary commands through the `S` HTTP header. It requires admin credentials to modify settings and trigger the payload.
Description
Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to execute arbitrary PHP code via a crafted option_new[report_w_day] parameter in a preferenze action, which can be later accessed via option/php-stats-options.php.
Exploits (1)
This exploit leverages a vulnerability in Php-Stats <= 0.1.9.1b to inject PHP code via the `report_w_day` parameter, then executes arbitrary commands through the `S` HTTP header. It requires admin credentials to modify settings and trigger the payload.