CVE-2007-5175
actsite 1.991 Beta - Remote Code Execution via BaseCfg[BaseDir] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5175. PoCs published by DNX.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in actSite v1.991 Beta due to improper input validation in the $BaseCfg[BaseDir] parameter in lib/base.php. An attacker can include a remote shell by manipulating the BaseDir parameter.
Description
PHP remote file inclusion vulnerability lib/base.php in actSite 1.991 Beta allows remote attackers to execute arbitrary PHP code via a URL in the BaseCfg[BaseDir] parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in actSite v1.991 Beta due to improper input validation in the $BaseCfg[BaseDir] parameter in lib/base.php. An attacker can include a remote shell by manipulating the BaseDir parameter.