Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-0699. PoCs published by laurent gaffié.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in PHP Web Portail by manipulating the 'site_path' parameter in includes.php to include a remote shell. The vulnerability allows arbitrary code execution if allow_url_include is enabled.
Description
PHP remote file inclusion vulnerability in includes/includes.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) before 2.5.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in PHP Web Portail by manipulating the 'site_path' parameter in includes.php to include a remote shell. The vulnerability allows arbitrary code execution if allow_url_include is enabled.