CVE-2007-3371
Powl 0.94 - Remote File Inclusion via _POWL[installPath] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3371. PoCs published by Kw3[R]Ln.
AI-analyzed exploit summary This exploit targets a Remote File Inclusion (RFI) vulnerability in POWL 0.94 by injecting a malicious script via the `_POWL[installPath]` parameter. It allows remote command execution by fetching and executing arbitrary commands from a remote URL.
Description
PHP remote file inclusion vulnerability in plugins/widgets/htmledit/htmledit.php in Powl 0.94 allows remote attackers to execute arbitrary PHP code via a URL in the _POWL[installPath] parameter.
Exploits (1)
This exploit targets a Remote File Inclusion (RFI) vulnerability in POWL 0.94 by injecting a malicious script via the `_POWL[installPath]` parameter. It allows remote command execution by fetching and executing arbitrary commands from a remote URL.