CVE-2007-6585
nmnnewsletter 1.0.7 - Remote Code Execution via confirmUnsubscription.php output Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-6585. PoCs published by CraCkEr.
AI-analyzed exploit summary This exploit leverages a Remote File Include (RFI) vulnerability in NmnNewsletter 1.0.7 via the 'output' parameter in confirmUnsubscription.php. It allows remote attackers to execute arbitrary code by including a malicious shell.
Description
PHP remote file inclusion vulnerability in confirmUnsubscription.php in NmnNewsletter 1.0.7 allows remote attackers to execute arbitrary PHP code via a URL in the output parameter.
Exploits (1)
This exploit leverages a Remote File Include (RFI) vulnerability in NmnNewsletter 1.0.7 via the 'output' parameter in confirmUnsubscription.php. It allows remote attackers to execute arbitrary code by including a malicious shell.