CVE-2007-3451
6ALBlog - Authenticated Remote File Inclusion via admin/index.php pg Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3451. PoCs published by Crackers_Child.
AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in 6ALBlog, allowing an attacker to extract user credentials (username and password) via a crafted SQL query. It also includes a remote file inclusion (RFI) exploit path for post-authentication exploitation.
Description
PHP remote file inclusion vulnerability in admin/index.php in 6ALBlog allows remote authenticated administrators to execute arbitrary PHP code via a URL in the pg parameter.
Exploits (1)
The exploit demonstrates a SQL injection vulnerability in 6ALBlog, allowing an attacker to extract user credentials (username and password) via a crafted SQL query. It also includes a remote file inclusion (RFI) exploit path for post-authentication exploitation.