CVE-2007-0633
MyNews < 4.2.2 - Remote File Inclusion via myNewsConf[path][sys][index] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0633. PoCs published by GoLd_M.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in MyNews 4.2.2. The vulnerability is due to improper input validation in the 'myNewsConf[path][sys][index]' parameter, allowing an attacker to include and execute arbitrary remote files.
Description
PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in MyNews 4.2.2. The vulnerability is due to improper input validation in the 'myNewsConf[path][sys][index]' parameter, allowing an attacker to include and execute arbitrary remote files.