CVE-2007-5055
izicontents < 1_rc6 - Remote File Inclusion via Path Traversal in admin_home or rootdp Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5055. PoCs published by irk4z.
AI-analyzed exploit summary This exploit demonstrates multiple remote and local file inclusion vulnerabilities in iziContents <= RC6. It provides URLs to exploit RFI, LFI, and file disclosure flaws by manipulating the 'gsLanguage' and 'rootdp' parameters.
Description
Multiple directory traversal vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the admin_home parameter to modules/poll/poll_summary.php or (2) the rootdp parameter to include/db.php.
Exploits (1)
This exploit demonstrates multiple remote and local file inclusion vulnerabilities in iziContents <= RC6. It provides URLs to exploit RFI, LFI, and file disclosure flaws by manipulating the 'gsLanguage' and 'rootdp' parameters.