CVE-2007-6325
Fastpublish CMS 1.9999 - Remote File Inclusion via config[fsBase] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-6325. PoCs published by RoMaNcYxHaCkEr.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Fastpublish CMS 1.9999 via the `config[fsBase]` parameter in `designconfig.php`. The PoC shows how an attacker can include a remote shell (e.g., c99.txt) by manipulating the parameter.
Description
PHP remote file inclusion vulnerability in adminbereich/designconfig.php in Fastpublish CMS 1.9999 allows remote attackers to execute arbitrary PHP code via a URL in the config[fsBase] parameter, a different vector than CVE-2006-2726.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Fastpublish CMS 1.9999 via the `config[fsBase]` parameter in `designconfig.php`. The PoC shows how an attacker can include a remote shell (e.g., c99.txt) by manipulating the parameter.