Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-6395. PoCs published by KiNgOfThEwOrLd.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Flat PHP Board <= 1.2, including remote command execution via file upload, directory traversal, and credential disclosure. It provides functional PoC code for RCE by injecting PHP code into user registration fields.
Description
Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain credentials via a direct request for the username php file for any user account in users/.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in Flat PHP Board <= 1.2, including remote command execution via file upload, directory traversal, and credential disclosure. It provides functional PoC code for RCE by injecting PHP code into user registration fields.