CVE-2008-5210
PhpBlock A8.5 - Remote Code Execution via PATH_TO_CODE Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5210. PoCs published by CraCkEr.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in PhpBlock a8.5, allowing an attacker to include arbitrary remote files via the PATH_TO_CODE parameter in multiple scripts. The exploit requires register_globals to be enabled.
Description
Multiple PHP remote file inclusion vulnerabilities in PhpBlock A8.5 allow remote attackers to execute arbitrary PHP code via a URL in the PATH_TO_CODE parameter to (1) script/init/createallimagecache.php, (2) allincludefortick.php and (3) test.php in script/tick/, and (4) modules/dungeon/tick/allincludefortick.php, different vectors than CVE-2008-1776.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in PhpBlock a8.5, allowing an attacker to include arbitrary remote files via the PATH_TO_CODE parameter in multiple scripts. The exploit requires register_globals to be enabled.