CVE-2007-1795
JCcorp URLshrink 1.3.1 - Remote Code Execution via Email Address Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1795. PoCs published by Dj7xpl.
AI-analyzed exploit summary This exploit leverages a file inclusion vulnerability in Urlshrink 1.3.1 by injecting malicious PHP code into the 'Email Address' field, which is then stored and executed via a predictable folder name in the 'data/tally.php' endpoint.
Description
JCcorp URLshrink 1.3.1 allows remote attackers to execute arbitrary PHP code via the email address field in an HTML link. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This exploit leverages a file inclusion vulnerability in Urlshrink 1.3.1 by injecting malicious PHP code into the 'Email Address' field, which is then stored and executed via a predictable folder name in the 'data/tally.php' endpoint.