CVE-2007-1715
Free Image Hosting 2.0 - Remote File Inclusion via AD_BODY_TEMP Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1715. PoCs published by Crackers_Child.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Free Image Hosting 2.0, allowing an attacker to include arbitrary files via the 'AD_BODY_TEMP' parameter in multiple PHP scripts. The exploit provides clear examples of malicious URLs to trigger the vulnerability.
Description
PHP remote file inclusion vulnerability in frontpage.php in Free Image Hosting 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. NOTE: the forgot_pass.php vector is already covered by CVE-2006-5670, and the login.php vector overlaps CVE-2006-5763.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in Free Image Hosting 2.0, allowing an attacker to include arbitrary files via the 'AD_BODY_TEMP' parameter in multiple PHP scripts. The exploit provides clear examples of malicious URLs to trigger the vulnerability.