CVE-2007-5786
GoSamba 1.0.1 - Remote Code Execution via PHP File Inclusion in include_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5786. PoCs published by GoLd_M.
AI-analyzed exploit summary This exploit demonstrates multiple remote file inclusion vulnerabilities in GoSamba 1.0.1 by manipulating the 'include_path' parameter in various PHP scripts. The PoC provides URLs that can be used to include arbitrary remote files, potentially leading to remote code execution.
Description
Multiple PHP remote file inclusion vulnerabilities in GoSamba 1.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) HTML_oben.php, (2) inc_freigabe.php, (3) inc_freigabe1.php, or (4) inc_freigabe3.php in include/; (5) inc_group.php; (6) inc_manager.php; (7) inc_newgroup.php; (8) inc_smb_conf.php; (9) inc_user.php; or (10) main.php.
Exploits (1)
This exploit demonstrates multiple remote file inclusion vulnerabilities in GoSamba 1.0.1 by manipulating the 'include_path' parameter in various PHP scripts. The PoC provides URLs that can be used to include arbitrary remote files, potentially leading to remote code execution.