CVE-2007-3270
phpMyInventory 2.8 - Remote File Inclusion via strIncludePrefix Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3270. PoCs published by o0xxdark0o.
AI-analyzed exploit summary This exploit leverages a remote file inclusion vulnerability in phpMyInventory 2.8 by manipulating the `strIncludePrefix` parameter in `global.inc.php` to include a remote shell. The vulnerability allows arbitrary code execution due to improper input validation.
Description
PHP remote file inclusion vulnerability in Includes/global.inc.php in phpMyInventory 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the strIncludePrefix parameter.
Exploits (1)
This exploit leverages a remote file inclusion vulnerability in phpMyInventory 2.8 by manipulating the `strIncludePrefix` parameter in `global.inc.php` to include a remote shell. The vulnerability allows arbitrary code execution due to improper input validation.