CVE-2007-1459
WebCreator <= 0.2.6-rc3 - Remote File Inclusion via moddir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1459. PoCs published by the_day.
AI-analyzed exploit summary This is an advisory detailing a remote file inclusion vulnerability in WebCreator <= 0.2.6-rc3 due to improper input validation in the $moddir parameter. The advisory includes proof-of-concept URLs but no actual exploit code.
Description
Multiple PHP remote file inclusion vulnerabilities in WebCreator 0.2.6-rc3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the moddir parameter to (1) content/load.inc.php, (2) config/load.inc.php, (3) http/load.inc.php, and unspecified other files.
Exploits (1)
This is an advisory detailing a remote file inclusion vulnerability in WebCreator <= 0.2.6-rc3 due to improper input validation in the $moddir parameter. The advisory includes proof-of-concept URLs but no actual exploit code.