CVE-2007-0810
GeekLog - Remote File Inclusion via glConf[path_libraries] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0810. PoCs published by GoLd_M.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in GeekLog <= 2.x by manipulating the `glConf[path_libraries]` parameter in BaseView.php to include an arbitrary file. The vulnerability arises due to insufficient input validation.
Description
PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_libraries] parameter. NOTE: this might be a vulnerability in MVCnPHP rather than a vulnerability in GeekLog.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in GeekLog <= 2.x by manipulating the `glConf[path_libraries]` parameter in BaseView.php to include an arbitrary file. The vulnerability arises due to insufficient input validation.