CVE-2007-1025
VS-Link-Partner < 2.1 - Remote File Inclusion via gb_pfad Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1025. PoCs published by ajann.
AI-analyzed exploit summary This is a client-side JavaScript-based exploit for a Remote File Include (RFI) vulnerability in VS-Link-Partner <= 2.1. It constructs a malicious URL to include a remote shell script via the 'gb_pfad' parameter in 'functions_inc.php'.
Description
PHP remote file inclusion vulnerability in inc/functions_inc.php in VS-Link-Partner 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gb_pfad, or possibly script_pfad, parameter.
Exploits (1)
This is a client-side JavaScript-based exploit for a Remote File Include (RFI) vulnerability in VS-Link-Partner <= 2.1. It constructs a malicious URL to include a remote shell script via the 'gb_pfad' parameter in 'functions_inc.php'.