CVE-2007-2736
Achievo 1.1.0 - Remote File Inclusion via config_atkroot Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2736. PoCs published by Katatafish.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in Achievo 1.1.0 by manipulating the 'config_atkroot' parameter in index.php to include a remote shell. The vulnerability arises due to improper input validation in the atk.inc file.
Description
PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in Achievo 1.1.0 by manipulating the 'config_atkroot' parameter in index.php to include a remote shell. The vulnerability arises due to improper input validation in the atk.inc file.