CVE-2007-4329
Web News 1.1 - Remote File Inclusion via config[root_ordner] Parameter
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2007-4329. PoCs published by Rizgar.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in WebNews 1.1 due to insufficient input sanitization. An attacker can include a remote file containing malicious code via the 'config[root_ordner]' parameter, leading to remote code execution.
Description
Multiple PHP remote file inclusion vulnerabilities in Web News 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) index.php, (2) news.php, or (3) feed.php.
Exploits (3)
This exploit demonstrates a remote file inclusion vulnerability in WebNews 1.1 due to insufficient input sanitization. An attacker can include a remote file containing malicious code via the 'config[root_ordner]' parameter, leading to remote code execution.
This exploit demonstrates a remote file inclusion vulnerability in WebNews 1.1 by injecting a malicious URL into the 'config[root_ordner]' parameter, allowing arbitrary code execution via a remote shell.
This exploit demonstrates a remote file inclusion vulnerability in WebNews 1.1 by injecting a malicious URL into the 'config[root_ordner]' parameter, allowing arbitrary code execution via a remote shell.