CVE-2007-2706
Media Gallery < 1.4.8a - Remote File Inclusion via _MG_CONF[path_html] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2706. PoCs published by ThE TiGeR.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Media Gallery <=v1.4. The vulnerability allows an attacker to include a remote shell by manipulating the `_MG_CONF[path_html]` parameter in `ftpmedia.php`.
Description
PHP remote file inclusion vulnerability in maint/ftpmedia.php in Media Gallery 1.4.8a and earlier for Geeklog allows remote attackers to execute arbitrary PHP code via a URL in the _MG_CONF[path_html] parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in Media Gallery <=v1.4. The vulnerability allows an attacker to include a remote shell by manipulating the `_MG_CONF[path_html]` parameter in `ftpmedia.php`.