CVE-2007-2608
Miplex2 Alpha 1 - Remote File Inclusion via Smarty Directory Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2608. PoCs published by ThE TiGeR.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Miplex2 by manipulating the 'system[smarty][dir]' parameter in SmartyFU.class.php to include arbitrary files. The attack allows remote code execution if the attacker can host a malicious file.
Description
PHP remote file inclusion vulnerability in lib/smarty/SmartyFU.class.php in Miplex2 Alpha 1 allows remote attackers to execute arbitrary PHP code via a URL in the system[smarty][dir] parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in Miplex2 by manipulating the 'system[smarty][dir]' parameter in SmartyFU.class.php to include arbitrary files. The attack allows remote code execution if the attacker can host a malicious file.