CVE-2007-1059
Ultimate Fun Book 1.02 - Remote File Inclusion Code Execution
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1059. PoCs published by kezzap66345.
AI-analyzed exploit summary This exploit leverages a file inclusion vulnerability in Ultimate Fun Book 1.02 by manipulating the 'gbpfad' parameter in function.php to include a remote script. The attack allows arbitrary code execution if allow_url_include is enabled.
Description
PHP remote file inclusion vulnerability in function.php in Ultimate Fun Book 1.02 allows remote attackers to execute arbitrary PHP code via a URL in the gbpfad parameter. NOTE: some sources mention "Ultimate Fun Board," but this appears to be an error.
Exploits (1)
This exploit leverages a file inclusion vulnerability in Ultimate Fun Book 1.02 by manipulating the 'gbpfad' parameter in function.php to include a remote script. The attack allows arbitrary code execution if allow_url_include is enabled.