Exploitation Summary
EIP tracks 3 public exploits for CVE-2007-2290. PoCs published by alijsb.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in B2 0.6.1 due to insufficient input sanitization in the 'b2inc' parameter of b2mail.php. An attacker can include arbitrary remote files, potentially leading to remote code execution.
Description
Multiple PHP remote file inclusion vulnerabilities in B2 Weblog and News Publishing Tool 0.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the b2inc parameter to (1) b2archives.php, (2) b2categories.php, or (3) b2mail.php. NOTE: this may overlap CVE-2002-1466.
Exploits (3)
This exploit demonstrates a remote file inclusion vulnerability in B2 0.6.1 due to insufficient input sanitization in the 'b2inc' parameter of b2mail.php. An attacker can include arbitrary remote files, potentially leading to remote code execution.
This exploit demonstrates a remote file inclusion vulnerability in B2 0.6.1 due to insufficient input sanitization. An attacker can include a remote shell by manipulating the 'b2inc' parameter in the 'b2categories.php' file.
This exploit demonstrates a remote file inclusion vulnerability in B2 0.6.1 due to insufficient input sanitization. An attacker can include a remote shell by manipulating the 'b2inc' parameter in the 'b2archives.php' file.