CVE-2007-1118
efiction < 3.1.1 - Remote File Inclusion via path_to_smf Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1118. PoCs published by ThE dE@Th.
AI-analyzed exploit summary This exploit leverages a file inclusion vulnerability in eFiction 3.1 by manipulating the `path_to_smf` parameter in `logout.php` and `get_session_vars.php` to include a remote shell. The vulnerability allows arbitrary file inclusion, leading to potential remote code execution.
Description
Multiple PHP remote file inclusion vulnerabilities in eFiction 3.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path_to_smf parameter to (1) bridges/SMF/logout.php or (2) get_session_vars.php.
Exploits (1)
This exploit leverages a file inclusion vulnerability in eFiction 3.1 by manipulating the `path_to_smf` parameter in `logout.php` and `get_session_vars.php` to include a remote shell. The vulnerability allows arbitrary file inclusion, leading to potential remote code execution.