CVE-2007-2594
phpmyportal 3.0.0 RC3 - Remote File Inclusion via GLOBALS[CHEMINMODULES] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2594. PoCs published by GoLd_M.
AI-analyzed exploit summary This is a remote file inclusion (RFI) exploit for phpMyPortal 3.0.0 RC3, leveraging the GLOBALS[CHEMINMODULES] parameter to include a remote shell. The exploit uses JavaScript to construct and submit a malicious URL to the target.
Description
PHP remote file inclusion vulnerability in inc/articles.inc.php in phpMyPortal 3.0.0 RC3 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[CHEMINMODULES] parameter.
Exploits (1)
This is a remote file inclusion (RFI) exploit for phpMyPortal 3.0.0 RC3, leveraging the GLOBALS[CHEMINMODULES] parameter to include a remote shell. The exploit uses JavaScript to construct and submit a malicious URL to the target.