CVE-2007-6542
Arcadem < 2.04 - Remote Code Execution via admin/frontpage_right.php loadadminpage Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-6542. PoCs published by KnocKout.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in Arcadem LE <= 2.04. The vulnerability exists in the 'frontpage_right.php' file due to improper sanitization of the 'loadadminpage' parameter, allowing remote file inclusion.
Description
PHP remote file inclusion vulnerability in admin/frontpage_right.php in Arcadem LE 2.04 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the loadadminpage parameter.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in Arcadem LE <= 2.04. The vulnerability exists in the 'frontpage_right.php' file due to improper sanitization of the 'loadadminpage' parameter, allowing remote file inclusion.