CVE-2007-3297
Musoo 0.21 - Remote File Inclusion via GLOBALS[ini_array][EXTLIB_PATH] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3297. PoCs published by GoLd_M.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Musoo 0.21 by manipulating the GLOBALS[ini_array][EXTLIB_PATH] parameter to include arbitrary remote files. The vulnerability exists in multiple PHP files due to improper input validation.
Description
Multiple PHP remote file inclusion vulnerabilities in Musoo 0.21 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[ini_array][EXTLIB_PATH] parameter to (1) msDb.php, (2) modules/MusooTemplateLite.php, or (3) modules/SoundImporter.php.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in Musoo 0.21 by manipulating the GLOBALS[ini_array][EXTLIB_PATH] parameter to include arbitrary remote files. The vulnerability exists in multiple PHP files due to improper input validation.