CVE-2007-2457
Pixaria Gallery < 1.4.3 - Remote File Inclusion via cfg[sys][base_path] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2457. PoCs published by irvian.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in Pixaria Gallery 1.x via the 'cfg[sys][base_path]' parameter in 'class.Smarty.php'. The attacker can include arbitrary remote PHP code by manipulating the parameter.
Description
PHP remote file inclusion vulnerability in resources/includes/class.Smarty.php in Pixaria Gallery before 1.4.3 allows remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in Pixaria Gallery 1.x via the 'cfg[sys][base_path]' parameter in 'class.Smarty.php'. The attacker can include arbitrary remote PHP code by manipulating the parameter.