Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-2009. PoCs published by Dr.RoVeR.
AI-analyzed exploit summary This exploit leverages a file inclusion vulnerability in SimpCMS Light's index.php, allowing remote attackers to include arbitrary PHP scripts via the 'site' parameter. The vulnerability is due to improper input validation in line 31 of index.php.
Description
PHP remote file inclusion vulnerability in index.php in SimpCMS Light 04.10.2007 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site parameter.
Exploits (1)
This exploit leverages a file inclusion vulnerability in SimpCMS Light's index.php, allowing remote attackers to include arbitrary PHP scripts via the 'site' parameter. The vulnerability is due to improper input validation in line 31 of index.php.