CVE-2007-3358
SerWeb < 0.9.6 - Remote File Inclusion via _SERWEB[serwebdir] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3358. PoCs published by Kw3[R]Ln.
AI-analyzed exploit summary This Perl script exploits a remote file inclusion vulnerability in SerWeb 0.9.4 by injecting a malicious URL into the `_SERWEB[serwebdir]` parameter, allowing arbitrary command execution via a remote shell script.
Description
PHP remote file inclusion vulnerability in html/load_lang.php in SerWeb 0.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _SERWEB[serwebdir] parameter.
Exploits (1)
This Perl script exploits a remote file inclusion vulnerability in SerWeb 0.9.4 by injecting a malicious URL into the `_SERWEB[serwebdir]` parameter, allowing arbitrary command execution via a remote shell script.