CVE-2007-2303
News Manager Deluxe 1.0.1 - Remote File Inclusion via Template Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2303. PoCs published by BeyazKurt.
AI-analyzed exploit summary This Perl script exploits a Local File Inclusion (LFI) vulnerability in NMDeluxe 1.0.1 by injecting malicious code into Apache log files and then including them via a vulnerable parameter. It provides a pseudo-shell for command execution.
Description
Directory traversal vulnerability in includes/footer.php in News Manager Deluxe (NMDeluxe) 1.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter.
Exploits (1)
This Perl script exploits a Local File Inclusion (LFI) vulnerability in NMDeluxe 1.0.1 by injecting malicious code into Apache log files and then including them via a vulnerable parameter. It provides a pseudo-shell for command execution.