Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-4636. PoCs published by GoLd_M.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in phpBG 0.9.1 by manipulating the 'rootdir' parameter in multiple scripts to include arbitrary remote files. The PoC provides specific paths and parameters to exploit the vulnerability.
Description
Multiple PHP remote file inclusion vulnerabilities in phpBG 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter to (1) intern/admin/other/backup.php, (2) intern/admin/, (3) intern/clan/member_add.php, (4) intern/config/key_2.php, or (5) intern/config/forum.php.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in phpBG 0.9.1 by manipulating the 'rootdir' parameter in multiple scripts to include arbitrary remote files. The PoC provides specific paths and parameters to exploit the vulnerability.