CVE-2005-2846
CMS Made Simple <= 0.10 - Remote File Inclusion via lang.php nls Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-2846. PoCs published by groszynskif.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in CMS Made Simple by manipulating the `nls[file][vx][vxsfx]` parameter to include arbitrary remote PHP code. The attacker can execute code with the privileges of the web server process.
Description
PHP remote file inclusion vulnerability in lang.php in CMS Made Simple 0.10 and earlier allows remote attackers to execute arbitrary PHP code via the nls[file][vx][vxsfx] parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in CMS Made Simple by manipulating the `nls[file][vx][vxsfx]` parameter to include arbitrary remote PHP code. The attacker can execute code with the privileges of the web server process.