20793vdb entry
http://www.securityfocus.com/bid/20793 CVE-2006-7184
Exhibit Engine 1.22 - 'fetchsettings.php?toroot' Remote File Inclusion
Record summary
CVE-2006-7184 has a selected CVSS score of 6.8; EIP currently links 2 catalogued exploits.
Description
Multiple PHP remote file inclusion vulnerabilities in Exhibit Engine (EE) 1.22, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the toroot parameter to (1) fetchsettings.php or (2) fstyles.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBExhibit Engine 1.22 - 'fetchsettings.php?toroot' Remote File InclusionExploitDB exploitby Cyber SecurityNot analyzed1 file
ExploitDBExhibit Engine 1.22 - 'fstyles.php?toroot' Remote File InclusionExploitDB exploitby Cyber SecurityNot analyzed1 file
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-7184