CVE-2010-0678
Katalog Stron Hurricane 1.3.5 - Remote Code Execution via includes_directory Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-0678. PoCs published by kaMtiEz.
AI-analyzed exploit summary This is a writeup detailing RFI and SQL injection vulnerabilities in Katalog Stron Hurricane version 1.3.5 or lower. It provides exploit paths and example payloads but does not include functional exploit code.
Description
PHP remote file inclusion vulnerability in includes/moderation.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the includes_directory parameter.
Exploits (1)
This is a writeup detailing RFI and SQL injection vulnerabilities in Katalog Stron Hurricane version 1.3.5 or lower. It provides exploit paths and example payloads but does not include functional exploit code.