CVE-2003-1086

pMachine Free/Pro <2.2.1 - RCE

Title source: llm
STIX 2.1

Description

PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote attackers to execute arbitrary PHP code by modifying the pm_path parameter to reference a URL on a remote web server that contains the code.

Exploits (1)

exploitdb WORKING POC VERIFIED
by frog · textwebappsphp
https://www.exploit-db.com/exploits/22776

References (2)

Core 2
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=105638414205498&w=2

Scores

EPSS 0.0389
EPSS Percentile 88.3%

Details

Status published
Products (3)
pmachine/pmachine_free
pmachine/pmachine_pro 2.2
pmachine/pmachine_pro 2.2.1
Published Jun 17, 2003
Tracked Since Feb 18, 2026