CVE-2007-0704
Somery 0.4.6 - Remote File Inclusion via install.php skindir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0704. PoCs published by basher13.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Somery 0.4.6 due to improper input validation in the 'skindir' parameter. An attacker can include arbitrary remote files by manipulating the 'skindir' parameter in the URL.
Description
PHP remote file inclusion vulnerability in install.php in Somery 0.4.6 allows remote attackers to execute arbitrary PHP code via a URL in the skindir parameter, a different vector than CVE-2006-4669. NOTE: the documentation says to remove install.php after installation.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in Somery 0.4.6 due to improper input validation in the 'skindir' parameter. An attacker can include arbitrary remote files by manipulating the 'skindir' parameter in the URL.