Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-6624. PoCs published by irk4z.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in PNphpBB2 <= 1.2i via the 'phpEx' parameter in printview.php. The vulnerability allows an attacker to read arbitrary files on the server by manipulating the parameter to traverse directories.
Description
Directory traversal vulnerability in printview.php in PNphpBB2 1.2i and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the phpEx parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in PNphpBB2 <= 1.2i via the 'phpEx' parameter in printview.php. The vulnerability allows an attacker to read arbitrary files on the server by manipulating the parameter to traverse directories.