CVE-2007-2969
WAnewsletter < 2.1.3 - Remote File Inclusion via waroot Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2969. PoCs published by Mogatil.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in WAnewsletter-2.1.3. The vulnerability arises from insecure handling of the 'waroot' parameter in newsletter.php, allowing an attacker to include arbitrary remote files.
Description
PHP remote file inclusion vulnerability in newsletter.php in WAnewsletter 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the waroot parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in WAnewsletter-2.1.3. The vulnerability arises from insecure handling of the 'waroot' parameter in newsletter.php, allowing an attacker to include arbitrary remote files.