Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-1439. PoCs published by K-159.
AI-analyzed exploit summary This is a writeup describing a Remote File Inclusion (RFI) vulnerability in MySQL Commander <= 2.7 due to unsanitized input in the $home variable. The exploit requires register_globals and allow_url_fopen to be enabled.
Description
PHP remote file inclusion vulnerability in ressourcen/dbopen.php in bitesser MySQL Commander 2.7 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the home parameter.
Exploits (1)
This is a writeup describing a Remote File Inclusion (RFI) vulnerability in MySQL Commander <= 2.7 due to unsanitized input in the $home variable. The exploit requires register_globals and allow_url_fopen to be enabled.