Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-0757. PoCs published by ThE dE@Th.
AI-analyzed exploit summary This exploit leverages a file inclusion vulnerability in the 'index.php' script of DreamStats System by manipulating the 'rootpath' parameter to include a remote shell. The vulnerability arises due to insufficient input validation, allowing arbitrary file inclusion.
Description
PHP remote file inclusion vulnerability in index.php in Miguel Nunes Call of Duty 2 (CoD2) DreamStats System 4.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter.
Exploits (1)
This exploit leverages a file inclusion vulnerability in the 'index.php' script of DreamStats System by manipulating the 'rootpath' parameter to include a remote shell. The vulnerability arises due to insufficient input validation, allowing arbitrary file inclusion.