Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-6399. PoCs published by KiNgOfThEwOrLd.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Flat PHP Board <= 1.2, including remote command execution via file upload, directory traversal, and credential disclosure. It provides functional PoC code for RCE by injecting PHP code into user registration fields.
Description
index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current user account by reading the password parameter value in the HTML source for the page generated by a profile action.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in Flat PHP Board <= 1.2, including remote command execution via file upload, directory traversal, and credential disclosure. It provides functional PoC code for RCE by injecting PHP code into user registration fields.