CVE-2007-1643

LAN Management System < 1.8.9 - Remote Code Execution via PHP File Inclusion

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-1643. PoCs published by Kacper.

AI-analyzed exploit summary The code describes a Remote File Inclusion (RFI) vulnerability in LMS <= 1.8.9, where attacker-controlled input in the 'CONFIG[directories][userpanel_dir]' and '_LIB_DIR' parameters can lead to arbitrary file inclusion. No actual exploit code is provided, only vulnerability details.

Description

Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG[directories][userpanel_dir] parameter to userpanel.php or the (2) _LIB_DIR parameter to welcome.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Kacper · textwebappsphp
https://www.exploit-db.com/exploits/3545

The code describes a Remote File Inclusion (RFI) vulnerability in LMS <= 1.8.9, where attacker-controlled input in the 'CONFIG[directories][userpanel_dir]' and '_LIB_DIR' parameters can lead to arbitrary file inclusion. No actual exploit code is provided, only vulnerability details.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: LMS <= 1.8.9
No auth needed
Prerequisites: Remote file inclusion must be enabled on the target server · Attacker must be able to reach the vulnerable endpoints
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1086
Third Party Advisory mailing-list x_refsource_vim
http://www.attrition.org/pipermail/vim/2007-April/001560.html
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/23099
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/33158
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/23100
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3545
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/24621

Scores

EPSS 0.1068
EPSS Percentile 95.2%

Details

CWE
CWE-94
Status published
Products (1)
lan_management_system/lan_management_system < 1.8.9
Published Mar 24, 2007
Tracked Since Feb 18, 2026