CVE-2007-6233
FTP Admin 0.1.0 - Authenticated Path Traversal via Page Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-6233. PoCs published by Omni.
AI-analyzed exploit summary The document describes multiple vulnerabilities in FTP Admin v0.1.0, including XSS, Local File Inclusion, and Admin Bypass. It provides PoC URLs but lacks executable exploit code.
Description
Directory traversal vulnerability in index.php in FTP Admin 0.1.0 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.
Exploits (1)
The document describes multiple vulnerabilities in FTP Admin v0.1.0, including XSS, Local File Inclusion, and Admin Bypass. It provides PoC URLs but lacks executable exploit code.