CVE-2007-0881
openi-cms - Remote File Inclusion via Seitenschutz Plugin Config Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0881. PoCs published by y3dips.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Openi CMS plugins (site protection) version 1.0. The vulnerability arises from unsanitized input in the 'oi_dir' variable, allowing an attacker to include a remote PHP file.
Description
PHP remote file inclusion vulnerability in the Seitenschutz plugin for OPENi-CMS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the (1) config[oi_dir] and possibly (2) config[openi_dir] parameters to open-admin/plugins/site_protection/index.php. NOTE: vector 2 might be the same as CVE-2006-4750.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in Openi CMS plugins (site protection) version 1.0. The vulnerability arises from unsanitized input in the 'oi_dir' variable, allowing an attacker to include a remote PHP file.