CVE-2008-6636
Geody Dagger r12feb2008 - Remote Code Execution via dir_edge_skins Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6636. PoCs published by CraCkEr.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in Dagger CMS. The exploit allows an attacker to include a remote shell by manipulating the 'dir_inc' parameter in the 'skins/default.php' file, leading to potential system compromise.
Description
PHP remote file inclusion vulnerability in skins/default.php in Geody Labs Dagger - The Cutting Edge r12feb2008, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the dir_edge_skins parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in Dagger CMS. The exploit allows an attacker to include a remote shell by manipulating the 'dir_inc' parameter in the 'skins/default.php' file, leading to potential system compromise.