Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-0758. PoCs published by Hasadya Raed.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in PHPProbid due to insufficient sanitization of user-supplied input in the 'lang' parameter. An attacker can include arbitrary remote files, potentially leading to remote code execution.
Description
PHP remote file inclusion vulnerability in lang.php in PHPProbid 5.24 allows remote attackers to execute arbitrary PHP code via a URL in the SRC attribute of an HTML element in the lang parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in PHPProbid due to insufficient sanitization of user-supplied input in the 'lang' parameter. An attacker can include arbitrary remote files, potentially leading to remote code execution.