CVE-2007-4737
SpeedTech PHP Library 0.8.0 - Remote File Inclusion via STPHPLIB_DIR Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-4737. PoCs published by leetsecurity.
AI-analyzed exploit summary This is a technical writeup describing a Remote File Inclusion (RFI) vulnerability in SpeedTech PHP Library. The vulnerability is due to improper input validation in the 'STPHPLIB_DIR' parameter, allowing remote attackers to include arbitrary files.
Description
Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the STPHPLIB_DIR parameter to (1) stphpapplication.php, (2) stphpbtnimage.php, or (3) stphpform.php.
Exploits (1)
This is a technical writeup describing a Remote File Inclusion (RFI) vulnerability in SpeedTech PHP Library. The vulnerability is due to improper input validation in the 'STPHPLIB_DIR' parameter, allowing remote attackers to include arbitrary files.