CVE-2007-4605
Virtual War < 1.5.0_r15 - Remote Code Execution via vwar_root Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-4605. PoCs published by DNX.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in VWar <= v1.5.0 R15 via the 'vwar_root' parameter in convert/mvcw.php. The PoC shows how an attacker can include a remote shell or execute arbitrary code by manipulating the parameter, with a warning that 'step=1' deletes database tables.
Description
PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter, a different vector than CVE-2006-1503, CVE-2006-1636, and CVE-2006-1747.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in VWar <= v1.5.0 R15 via the 'vwar_root' parameter in convert/mvcw.php. The PoC shows how an attacker can include a remote shell or execute arbitrary code by manipulating the parameter, with a warning that 'step=1' deletes database tables.