CVE-2007-0499
phpIndexPage <= 1.0.1 - Remote Code Execution via env[inc_path] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0499. PoCs published by DeltahackingTEAM.
AI-analyzed exploit summary This exploit targets a Remote File Include (RFI) vulnerability in phpindexpage 1.0 and 1.0.1 via the 'env[inc_path]' parameter in config.php. It allows an attacker to include a remote shell script and execute arbitrary commands on the target system.
Description
PHP remote file inclusion vulnerability in config.php in Sangwan Kim phpIndexPage 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[inc_path] parameter.
Exploits (1)
This exploit targets a Remote File Include (RFI) vulnerability in phpindexpage 1.0 and 1.0.1 via the 'env[inc_path]' parameter in config.php. It allows an attacker to include a remote shell script and execute arbitrary commands on the target system.