CVE-2007-2458
Pixaria Gallery - Remote File Inclusion via cfg[sys][base_path] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2458. PoCs published by irvian.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in Pixaria Gallery 1.x via the 'cfg[sys][base_path]' parameter in 'class.Smarty.php'. The attacker can include arbitrary remote PHP code by manipulating the parameter.
Description
Multiple PHP remote file inclusion vulnerabilities in Pixaria Gallery before 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter to psg.smarty.lib.php and certain include and library scripts, a different vector than CVE-2007-2457.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in Pixaria Gallery 1.x via the 'cfg[sys][base_path]' parameter in 'class.Smarty.php'. The attacker can include arbitrary remote PHP code by manipulating the parameter.