Exploitation Summary
EIP tracks 2 public exploits for CVE-2007-1424. PoCs published by Hasadya Raed.
AI-analyzed exploit summary The provided text describes a retired vulnerability report for DataLife Engine, which was initially believed to be prone to remote file inclusion but was later determined to be non-exploitable due to the vulnerable parameter being a constant.
Description
Multiple PHP remote file inclusion vulnerabilities in Softnews Media Group DataLife Engine allow remote attackers to execute arbitrary PHP code via a URL in the root_dir parameter to (1) init.php and (2) Ajax/editnews.php. NOTE: some of these details are obtained from third party information.
Exploits (2)
The provided text describes a retired vulnerability report for DataLife Engine, which was initially believed to be prone to remote file inclusion but was later determined to be non-exploitable due to the vulnerable parameter being a constant.
The provided text describes a retired vulnerability report for DataLife Engine, which was initially believed to be prone to remote file inclusion vulnerabilities but was later determined to be non-exploitable due to the vulnerable parameter being a constant.