CVE-2007-5149
North Country Public Radio Public Media Manager 1.3 - Remote Code Execution via NewsCMS indir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5149. PoCs published by 0in.
AI-analyzed exploit summary This exploit leverages a file inclusion vulnerability in PMM-CMS by manipulating the 'indir' parameter to include a remote shell. The vulnerability arises from improper input validation in 'news/newstopic_inc.php'.
Description
PHP remote file inclusion vulnerability in NewsCMS/news/newstopic_inc.php in North Country Public Radio Public Media Manager (PMM) 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the indir parameter.
Exploits (1)
This exploit leverages a file inclusion vulnerability in PMM-CMS by manipulating the 'indir' parameter to include a remote shell. The vulnerability arises from improper input validation in 'news/newstopic_inc.php'.