CVE-2007-1906

eCardMAX HotEditor 4.0 - Local File Inclusion via richedit/keyboard.php Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-1906. PoCs published by Liz0ziM.

AI-analyzed exploit summary This exploit targets a local file inclusion vulnerability in eCardMAX HotEditor 4.0, allowing unauthorized file access and script execution. The PoC sends a crafted request to 'keyboard.php' with a malicious 'first' parameter to include arbitrary files.

Description

Directory traversal vulnerability in richedit/keyboard.php in eCardMAX HotEditor (Hot Editor) 4.0, and the HotEditor plugin for MyBB, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the first parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Liz0ziM · perlwebappsphp
https://www.exploit-db.com/exploits/29827

This exploit targets a local file inclusion vulnerability in eCardMAX HotEditor 4.0, allowing unauthorized file access and script execution. The PoC sends a crafted request to 'keyboard.php' with a malicious 'first' parameter to include arbitrary files.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: eCardMAX HotEditor 4.0
No auth needed
Prerequisites: Target URL with vulnerable HotEditor installation
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/23377
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/33521
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1315
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/24825
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/34776
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/465092/100/0/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/465094/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/2533

Scores

EPSS 0.0323
EPSS Percentile 86.6%

Details

Status published
Products (2)
ecardmax.com/hot_editor 4.0
mybb/mybb_hot_editor_plugin
Published Apr 10, 2007
Tracked Since Feb 18, 2026