CVE-2008-1074
GROUP-E 1.6.41 - Remote Code Execution via CFG[PREPEND_FILE] Parameter
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1074. PoCs published by CraCkEr.
AI-analyzed exploit summary This exploit leverages a Remote File Include (RFI) vulnerability in GROUP-E 1.6.41 via the `CFG[PREPEND_FILE]` parameter in `head_auth.php`. It allows an attacker to include and execute arbitrary remote shell code, leading to potential system compromise.
Description
PHP remote file inclusion vulnerability in lib/head_auth.php in GROUP-E 1.6.41 allows remote attackers to execute arbitrary PHP code via a URL in the CFG[PREPEND_FILE] parameter.
Exploits (1)
This exploit leverages a Remote File Include (RFI) vulnerability in GROUP-E 1.6.41 via the `CFG[PREPEND_FILE]` parameter in `head_auth.php`. It allows an attacker to include and execute arbitrary remote shell code, leading to potential system compromise.