Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-6178. PoCs published by MhZ91.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in EHCP (Easy Hosting Control Panel) due to improper input validation in the 'confdir' parameter. The vulnerability allows remote attackers to include and execute arbitrary PHP code by manipulating the parameter in 'dbutil.bck.php' or 'dbutil.php'.
Description
Multiple PHP remote file inclusion vulnerabilities in Easy Hosting Control Panel for Ubuntu (EHCP) 0.22.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the confdir parameter to (1) dbutil.bck.php and (2) dbutil.php in config/.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in EHCP (Easy Hosting Control Panel) due to improper input validation in the 'confdir' parameter. The vulnerability allows remote attackers to include and execute arbitrary PHP code by manipulating the parameter in 'dbutil.bck.php' or 'dbutil.php'.