CVE-2007-5314
xkiosk_web 3.0.1i - Remote Code Execution via PEARPATH Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5314. PoCs published by h4ck3r.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in xKiosk WEB 3.0.1i due to improper handling of the PEARPATH parameter in xkurl.php. An attacker can include arbitrary remote files by manipulating the PEARPATH parameter.
Description
PHP remote file inclusion vulnerability in system/funcs/xkurl.php in xKiosk WEB 3.0.1i, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the PEARPATH parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in xKiosk WEB 3.0.1i due to improper handling of the PEARPATH parameter in xkurl.php. An attacker can include arbitrary remote files by manipulating the PEARPATH parameter.