CVE-2007-4815
Markus Iser ED Engine 0.8999 alpha - Remote Code Execution via Codebase Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-4815. PoCs published by MhZ91.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in WebED 0.8999. The vulnerability allows an attacker to include arbitrary remote files via the 'Codebase' parameter in multiple RSS module scripts.
Description
Multiple PHP remote file inclusion vulnerabilities in WebED in Markus Iser ED Engine 0.8999 alpha allow remote attackers to execute arbitrary PHP code via a URL in the Codebase parameter to (1) channeledit.php, (2) post.php, (3) view.php, or (4) viewitem.php in source/mod/rss/.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in WebED 0.8999. The vulnerability allows an attacker to include arbitrary remote files via the 'Codebase' parameter in multiple RSS module scripts.