CVE-2007-0172
AllMyGuests < 0.3 - Remote File Inclusion via AMG_serverpath Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0172. PoCs published by beks.
AI-analyzed exploit summary This is a writeup describing a Remote File Inclusion (RFI) vulnerability in AllMyGuests 3.0. It lists vulnerable parameters and endpoints but does not include executable exploit code.
Description
Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the AMG_serverpath parameter to (1) comments.php and (2) signin.php; and possibly via a URL in unspecified parameters to (3) include/submit.inc.php, (4) admin/index.php, (5) include/cm_submit.inc.php, and (6) index.php.
Exploits (1)
This is a writeup describing a Remote File Inclusion (RFI) vulnerability in AllMyGuests 3.0. It lists vulnerable parameters and endpoints but does not include executable exploit code.