CVE-2007-1771
Ay System Solutions Web Content System 2.7.1 - Remote File Inclusion via formjavascript.php
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1771. PoCs published by kezzap66345.
AI-analyzed exploit summary This is a client-side HTML/JavaScript exploit for a Remote File Include (RFI) vulnerability in Web Content System v2.7.1. It constructs a malicious URL to include a remote shell script via the 'path[JavascriptEdit]' parameter.
Description
PHP remote file inclusion vulnerability in manage/javascript/formjavascript.php in Ay System Solutions Web Content System (WCS) 2.7.1 allows remote attackers to execute arbitrary PHP code via a URL in the path[JavascriptEdit] parameter.
Exploits (1)
This is a client-side HTML/JavaScript exploit for a Remote File Include (RFI) vulnerability in Web Content System v2.7.1. It constructs a malicious URL to include a remote shell script via the 'path[JavascriptEdit]' parameter.