CVE-2003-1086

pMachine Free/Pro <2.2.1 - RCE

Title source: llm

Description

PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote attackers to execute arbitrary PHP code by modifying the pm_path parameter to reference a URL on a remote web server that contains the code.

Exploits (1)

exploitdb WORKING POC VERIFIED
by frog · textwebappsphp
https://www.exploit-db.com/exploits/22776

Scores

EPSS 0.0389
EPSS Percentile 88.1%

Classification

Status draft

Affected Products (3)

pmachine/pmachine_free
pmachine/pmachine_pro
pmachine/pmachine_pro

Timeline

Published Jun 17, 2003
Tracked Since Feb 18, 2026