CVE-2008-6403
openrat < 0.8-beta4 - Remote Code Execution via tpl_dir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6403. PoCs published by dun.
AI-analyzed exploit summary This is a writeup describing a Remote File Inclusion (RFI) vulnerability in OpenRat <= 0.8-beta4. The vulnerability exists in the `insert.inc.php` file due to improper sanitization of the `tpl_dir` parameter, allowing an attacker to include arbitrary remote files.
Description
PHP remote file inclusion vulnerability in themes/default/include/html/insert.inc.php in OpenRat 0.8-beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tpl_dir parameter.
Exploits (1)
This is a writeup describing a Remote File Inclusion (RFI) vulnerability in OpenRat <= 0.8-beta4. The vulnerability exists in the `insert.inc.php` file due to improper sanitization of the `tpl_dir` parameter, allowing an attacker to include arbitrary remote files.