CVE-2007-5157
PHP Fidonet Tosser 1.3.0 - Remote Code Execution via SRC_PATH Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5157. PoCs published by w0cker.
AI-analyzed exploit summary This is a writeup describing a Remote File Inclusion (RFI) vulnerability in phpFidoNode <= 1.3.0. The vulnerability exists in the 'phfito-post.php' file due to improper handling of the 'SRC_PATH' parameter, allowing remote attackers to include arbitrary files.
Description
PHP remote file inclusion vulnerability in phfito-post.php in Alex Kocharin PHP Fidonet Tosser (PhFiTo) 1.3.0 in phpFidoNode allows remote attackers to execute arbitrary PHP code via a URL in the SRC_PATH parameter to phfito-post.
Exploits (1)
This is a writeup describing a Remote File Inclusion (RFI) vulnerability in phpFidoNode <= 1.3.0. The vulnerability exists in the 'phfito-post.php' file due to improper handling of the 'SRC_PATH' parameter, allowing remote attackers to include arbitrary files.