CVE-2008-1051
phpProfiles 4.5.2 BETA - Remote Code Execution via include/body_comm.inc.php content Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1051. PoCs published by CraCkEr.
AI-analyzed exploit summary This exploit leverages a Remote File Include (RFI) vulnerability in phpProfiles 4.5.2 BETA by injecting a shell via the 'content' parameter in the 'body_comm.inc.php' file. It requires register_globals to be enabled for successful exploitation.
Description
PHP remote file inclusion vulnerability in include/body_comm.inc.php in phpProfiles 4.5.2 BETA allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.
Exploits (1)
This exploit leverages a Remote File Include (RFI) vulnerability in phpProfiles 4.5.2 BETA by injecting a shell via the 'content' parameter in the 'body_comm.inc.php' file. It requires register_globals to be enabled for successful exploitation.