CVE-2007-2327
HTMLeditbox 2.2 - Remote File Inclusion via settings[app_dir] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2327. PoCs published by alijsb.
AI-analyzed exploit summary The code describes a remote file inclusion vulnerability in htmlEditbox 2.2 due to insufficient sanitization of user-supplied data in the 'settings[app_dir]' parameter. An attacker can exploit this to execute arbitrary PHP code by including a remote shell.
Description
PHP remote file inclusion vulnerability in _editor.php in HTMLeditbox 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the settings[app_dir] parameter.
Exploits (1)
The code describes a remote file inclusion vulnerability in htmlEditbox 2.2 due to insufficient sanitization of user-supplied data in the 'settings[app_dir]' parameter. An attacker can exploit this to execute arbitrary PHP code by including a remote shell.