CVE-2007-1164
DBImageGallery 1.2.2 - Remote Code Execution via donsimg_base_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1164. PoCs published by Denven.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in DBImageGallery 1.2.2. The vulnerability arises from insecure usage of the `donsimg_base_path` parameter in multiple PHP scripts, allowing an attacker to include arbitrary remote files.
Description
Multiple PHP remote file inclusion vulnerabilities in DBImageGallery 1.2.2 allow remote attackers to execute arbitrary PHP code via a URL in the donsimg_base_path parameter to (1) attributes.php, (2) images.php, or (3) scan.php in admin/; or (4) attributes.php, (5) db_utils.php, (6) images.php, (7) utils.php, or (8) values.php in includes/.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in DBImageGallery 1.2.2. The vulnerability arises from insecure usage of the `donsimg_base_path` parameter in multiple PHP scripts, allowing an attacker to include arbitrary remote files.