CVE-2007-3522
sPHPell 1.01 - Remote File Inclusion via SpellIncPath Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3522. PoCs published by Mehmet Ince.
AI-analyzed exploit summary This is a writeup describing a Remote File Include (RFI) vulnerability in sphpell 1.01. It details multiple endpoints where the `SpellIncPath` parameter is vulnerable to RFI due to improper input validation.
Description
Multiple PHP remote file inclusion vulnerabilities in sPHPell 1.01 allow remote attackers to execute arbitrary PHP code via a URL in the SpellIncPath parameter to (1) spellcheckpageinc.php, (2) spellchecktext.php, (3) spellcheckwindow.php, or (4) spellcheckwindowframeset.php.
Exploits (1)
This is a writeup describing a Remote File Include (RFI) vulnerability in sphpell 1.01. It details multiple endpoints where the `SpellIncPath` parameter is vulnerable to RFI due to improper input validation.