CVE-2007-4231
IDevSpot PhpHostBot <= 1.06 - Remote File Inclusion via svr_rootscript Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-4231. PoCs published by K-159.
AI-analyzed exploit summary This is an advisory detailing a remote file inclusion vulnerability in PhpHostBot <= 1.06 due to improper input validation in the 'svr_rootscript' parameter. Exploitation requires 'register_globals' to be enabled.
Description
PHP remote file inclusion vulnerability in order/login.php in IDevSpot PhpHostBot 1.06 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the svr_rootscript parameter, a different vector than CVE-2007-4094 and CVE-2006-3776.
Exploits (1)
This is an advisory detailing a remote file inclusion vulnerability in PhpHostBot <= 1.06 due to improper input validation in the 'svr_rootscript' parameter. Exploitation requires 'register_globals' to be enabled.