CVE-2007-6230
Rayzz Script 2.0 - Path Traversal via CFG[site][project_path] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-6230. PoCs published by Crackers_Child.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Rayzz Script 2.0 by manipulating the `CFG[site][project_path]` parameter to include arbitrary local files via null byte injection.
Description
Directory traversal vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the CFG[site][project_path] parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Rayzz Script 2.0 by manipulating the `CFG[site][project_path]` parameter to include arbitrary local files via null byte injection.