CVE-2008-6740
HoMaP-CMS 0.1 - Remote Code Execution via _settings[pluginpath] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6740. PoCs published by CraCkEr.
AI-analyzed exploit summary This exploit leverages a Remote File Include (RFI) vulnerability in HoMaP-CMS 0.1 via the `_settings[pluginpath]` parameter in `plugin_admin.php`. It allows an attacker to include and execute arbitrary remote code, potentially leading to system compromise.
Description
PHP remote file inclusion vulnerability in html/admin/modules/plugin_admin.php in HoMaP-CMS 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the _settings[pluginpath] parameter.
Exploits (1)
This exploit leverages a Remote File Include (RFI) vulnerability in HoMaP-CMS 0.1 via the `_settings[pluginpath]` parameter in `plugin_admin.php`. It allows an attacker to include and execute arbitrary remote code, potentially leading to system compromise.