30673vdb entry
http://www.securityfocus.com/bid/30673 CVE-2008-6066
Meet#Web 0.8 - 'modules.php?root_path' Remote File Inclusion
Record summary
CVE-2008-6066 has a selected CVSS score of 7.5; EIP currently links 6 catalogued exploits.
Description
Multiple PHP remote file inclusion vulnerabilities in Meet#Web 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) modules.php, (2) ManagerResource.class.php, (3) ManagerRightsResource.class.php, (4) RegForm.class.php, (5) RegResource.class.php, and (6) RegRightsResource.class.php in classes/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 6
Proofs of concept
6Catalogued exploits
ExploitDBMeet#Web 0.8 - 'modules.php?root_path' Remote File InclusionExploitDB exploitby Rakesh SNot analyzed1 file
ExploitDBMeet#Web 0.8 - 'ManagerResource.class.php?root_path' Remote File InclusionExploitDB exploitby Rakesh SNot analyzed1 file
ExploitDBMeet#Web 0.8 - 'ManagerRightsResource.class.php?root_path' Remote File InclusionExploitDB exploitby Rakesh SNot analyzed1 file
ExploitDBMeet#Web 0.8 - 'RegForm.class.php?root_path' Remote File InclusionExploitDB exploitby Rakesh SNot analyzed1 file
ExploitDBMeet#Web 0.8 - 'RegResource.class.php?root_path' Remote File InclusionExploitDB exploitby Rakesh SNot analyzed1 file
ExploitDBMeet#Web 0.8 - 'RegRightsResource.class.php?root_path' Remote File InclusionExploitDB exploitby Rakesh SNot analyzed1 file
References
4securityfocus.com
http://www.securityfocus.com/bid/30673/exploit meetweb-rootpath-file-include(44454)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/44454 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-6066