CVE-2007-6488
Falcon Series One CMS 1.4.3 - Remote File Inclusion via dir[classes] or error Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-6488. PoCs published by MhZ91.
AI-analyzed exploit summary The exploit demonstrates multiple remote file inclusion (RFI) vulnerabilities in Falcon CMS, allowing arbitrary code execution via manipulated 'dir[classes]' and 'error' parameters. It also includes a permanent XSS and CSRF exploit for password change.
Description
Multiple PHP remote file inclusion vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the dir[classes] parameter to sitemap.xml.php or (2) the error parameter to errors.php.
Exploits (1)
The exploit demonstrates multiple remote file inclusion (RFI) vulnerabilities in Falcon CMS, allowing arbitrary code execution via manipulated 'dir[classes]' and 'error' parameters. It also includes a permanent XSS and CSRF exploit for password change.