CVE-2007-3621
AsteriDex < 3.0 - Remote Code Execution via CRLF Injection in callboth.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3621. PoCs published by Carl Livitt.
AI-analyzed exploit summary This exploit targets a command injection vulnerability in AsteriDex's callboth.php. It leverages SIP header injection to execute arbitrary commands, ultimately downloading and setting up a PHP shell for remote access.
Description
Multiple CRLF injection vulnerabilities in callboth.php in AsteriDex 3.0 and earlier allow remote attackers to inject arbitrary shell commands via the (1) IN and (2) OUT parameters.
Exploits (1)
This exploit targets a command injection vulnerability in AsteriDex's callboth.php. It leverages SIP header injection to execute arbitrary commands, ultimately downloading and setting up a PHP shell for remote access.