CVE-2008-1760
blogator-script < 1.00 - Remote Code Execution via incl_page Parameter
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1760. PoCs published by JIKO.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Blogator-script Version 2. The vulnerability allows an attacker to include arbitrary remote files via the 'incl_page' parameter in multiple PHP files, potentially leading to remote code execution.
Description
Multiple PHP remote file inclusion vulnerabilities in Blogator-script before 1.01 allow remote attackers to execute arbitrary PHP code via a URL in the incl_page parameter in (1) struct_admin.php, (2) struct_admin_blog.php, and (3) struct_main.php in _blogadata/include.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Blogator-script Version 2. The vulnerability allows an attacker to include arbitrary remote files via the 'incl_page' parameter in multiple PHP files, potentially leading to remote code execution.