CVE-2007-5388
WebDesktop 0.1 - Remote Code Execution via PHP File Inclusion
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5388. PoCs published by S.W.A.T..
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in WebDesktop 0.1. The vulnerability arises from insecure file inclusion in the 'apps.php' and 'wsk.php' scripts, allowing an attacker to include arbitrary remote files by manipulating the 'app' or 'wsk' parameters.
Description
Multiple PHP remote file inclusion vulnerabilities in WebDesktop 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) app parameter to apps/apps.php and the (2) wsk parameter to wsk/wsk.php.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in WebDesktop 0.1. The vulnerability arises from insecure file inclusion in the 'apps.php' and 'wsk.php' scripts, allowing an attacker to include arbitrary remote files by manipulating the 'app' or 'wsk' parameters.