CVE-2007-4327
File Uploader 1.1 - Remote File Inclusion via config[root_ordner] Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-4327. PoCs published by Rizgar.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in File Uploader 1.1 by injecting a malicious URL into the 'config[root_ordner]' parameter, allowing arbitrary code execution via a remote shell.
Description
Multiple PHP remote file inclusion vulnerabilities in File Uploader 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) index.php or (2) datei.php.
Exploits (2)
This exploit demonstrates a remote file inclusion vulnerability in File Uploader 1.1 by injecting a malicious URL into the 'config[root_ordner]' parameter, allowing arbitrary code execution via a remote shell.
This exploit demonstrates a remote file inclusion vulnerability in File Uploader 1.1 by injecting a malicious URL into the 'config[root_ordner]' parameter, allowing arbitrary code execution via a remote shell.