CVE-2007-0867
Site-Assistant < 0990 - Remote File Inclusion via paths[version] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0867. PoCs published by ajann.
AI-analyzed exploit summary This is a client-side HTML/JavaScript exploit for a remote file inclusion (RFI) vulnerability in Site-Assistant <= v0990. It constructs a malicious URL to include a remote shell script via the 'paths[version]' parameter.
Description
PHP remote file inclusion vulnerability in classes/menu.php in Site-Assistant 0990 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the paths[version] parameter.
Exploits (1)
This is a client-side HTML/JavaScript exploit for a remote file inclusion (RFI) vulnerability in Site-Assistant <= v0990. It constructs a malicious URL to include a remote shell script via the 'paths[version]' parameter.