CVE-2007-1165
DBGuestbook 1.1 - Remote Code Execution via dbs_base_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1165. PoCs published by Denven.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in DBGuestBook 1.1. The vulnerability allows an attacker to include arbitrary remote files via the 'dbs_base_path' parameter in multiple PHP scripts.
Description
Multiple PHP remote file inclusion vulnerabilities in DBGuestbook 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the dbs_base_path parameter to (1) utils.php, (2) guestbook.php, or (3) views.php in includes/.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in DBGuestBook 1.1. The vulnerability allows an attacker to include arbitrary remote files via the 'dbs_base_path' parameter in multiple PHP scripts.