CVE-2007-2816
ol_bookmarks 0.7.4 - Remote Code Execution via Root Parameter in Theme Files
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-2816. PoCs published by ThE TiGeR.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Olbookmarks <= 0.7.4. The vulnerability allows an attacker to include arbitrary remote files via the 'root' parameter in multiple PHP scripts, potentially leading to remote code execution.
Description
Multiple PHP remote file inclusion vulnerabilities in ol'bookmarks 0.7.4 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) test1.php, (2) blackorange.php, (3) default.php, (4) frames1.php, (5) frames1_top.php, (7) test2.php, (8) test3.php, (9) test4.php, (10) test5.php, (11) test6.php, (12) frames1_left.php, and (13) frames1_center.php in themes/.
Exploits (2)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Olbookmarks <= 0.7.4. The vulnerability allows an attacker to include arbitrary remote files via the 'root' parameter in multiple PHP scripts, potentially leading to remote code execution.
This exploit demonstrates a SQL injection vulnerability in Ol Bookmarks Manager 0.7.4, allowing an attacker to extract sensitive information (e.g., passwords and logins) from the 'preferences' table via a crafted URL parameter.