CVE-2007-0576
Xt-Stats 2.3.x to 2.4.0.b3 - Remote File Inclusion Code Execution
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0576. PoCs published by ThE dE@Th.
AI-analyzed exploit summary This exploit leverages a file inclusion vulnerability in xt_counter.php by manipulating the server_base_dir parameter to execute arbitrary PHP code. The vulnerability arises due to insufficient input validation, allowing remote code execution.
Description
PHP remote file inclusion vulnerability in xt_counter.php in Xt-Stats 2.3.x up to 2.4.0.b3 allows remote attackers to execute arbitrary PHP code via a URL in the server_base_dir parameter.
Exploits (1)
This exploit leverages a file inclusion vulnerability in xt_counter.php by manipulating the server_base_dir parameter to execute arbitrary PHP code. The vulnerability arises due to insufficient input validation, allowing remote code execution.