CVE-2007-4921
Ajax File Browser 3 Beta - Remote Code Execution via approot Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-4921. PoCs published by arfis project.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Ajax File Browser 3 Beta. The vulnerability is due to improper input validation in the 'approot' parameter in '_includes/settings.inc.php', allowing an attacker to include arbitrary remote files.
Description
PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attackers to execute arbitrary PHP code via a URL in the approot parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Ajax File Browser 3 Beta. The vulnerability is due to improper input validation in the 'approot' parameter in '_includes/settings.inc.php', allowing an attacker to include arbitrary remote files.