CVE-2003-1086
pMachine Free and Pro - Remote File Inclusion via pm_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2003-1086. PoCs published by frog.
AI-analyzed exploit summary This exploit leverages a file inclusion vulnerability in PMachine by manipulating the `pm_path` and `sfx` parameters to include remote files, leading to remote command execution. The attacker hosts malicious code on a remote server and tricks the application into including it.
Description
PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote attackers to execute arbitrary PHP code by modifying the pm_path parameter to reference a URL on a remote web server that contains the code.
Exploits (1)
This exploit leverages a file inclusion vulnerability in PMachine by manipulating the `pm_path` and `sfx` parameters to include remote files, leading to remote command execution. The attacker hosts malicious code on a remote server and tricks the application into including it.