CVE-2007-1766
Advanced Login < 0.76 - Remote File Inclusion via root Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1766. PoCs published by Bithedz.
AI-analyzed exploit summary The exploit describes a remote file inclusion vulnerability in Advanced Login <= 0.7 due to improper verification of the 'root' parameter in profiledit.php. This allows arbitrary PHP code execution by including external files.
Description
PHP remote file inclusion vulnerability in login/engine/db/profiledit.php in Advanced Login 0.76 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.
Exploits (1)
The exploit describes a remote file inclusion vulnerability in Advanced Login <= 0.7 due to improper verification of the 'root' parameter in profiledit.php. This allows arbitrary PHP code execution by including external files.