CVE-2007-5139
chupix_cms 0.2.3 - Remote Code Execution via Repertoire Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5139. PoCs published by 0in.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Chupix 0.2.3 due to improper input validation in the 'repertoire' parameter. An attacker can include a remote shell by manipulating the parameter in the URL.
Description
PHP remote file inclusion vulnerability in admin/include/header.php in chupix 0.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the repertoire parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Chupix 0.2.3 due to improper input validation in the 'repertoire' parameter. An attacker can include a remote shell by manipulating the parameter in the URL.