CVE-2007-0496
Neon Labs Website < 3.2 - Remote File Inclusion via g_strRootDir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0496. PoCs published by 3l3ctric-Cracker.
AI-analyzed exploit summary This exploit leverages a file inclusion vulnerability in nlws 3.2 due to improper input validation in the 'g_strRootDir' parameter. The PoC demonstrates arbitrary file inclusion, which can lead to remote code execution if combined with log poisoning or other techniques.
Description
PHP remote file inclusion vulnerability in lib/nl/nl.php in Neon Labs Website (nlws) 3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the g_strRootDir parameter.
Exploits (1)
This exploit leverages a file inclusion vulnerability in nlws 3.2 due to improper input validation in the 'g_strRootDir' parameter. The PoC demonstrates arbitrary file inclusion, which can lead to remote code execution if combined with log poisoning or other techniques.