CVE-2008-2270
PHPWAY Kostenloses Linkmanagementscript - Remote File Inclusion via main_page_directory or page_to_include Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2270. PoCs published by HaCkeR_EgY.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in 'Kostenloses Linkmanagementscript' due to unsanitized user input in the 'main_page_directory' and 'page_to_include' parameters. The PoC shows how an attacker can include arbitrary remote files, potentially leading to remote code execution.
Description
Multiple PHP remote file inclusion vulnerabilities in PHPWAY Kostenloses Linkmanagementscript allow remote attackers to execute arbitrary PHP code via a URL in the (1) main_page_directory and (2) page_to_include parameters in template\index.php.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in 'Kostenloses Linkmanagementscript' due to unsanitized user input in the 'main_page_directory' and 'page_to_include' parameters. The PoC shows how an attacker can include arbitrary remote files, potentially leading to remote code execution.