CVE-2007-2185

Supasite 1.23b - Remote Code Execution via supa[db_path] or supa[include_path] Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-2185. PoCs published by GoLd_M.

AI-analyzed exploit summary This is a writeup detailing multiple remote file inclusion vulnerabilities in Supasite v1.23b. It lists various endpoints where the 'supa[db_path]' or 'supa[include_path]' parameters can be manipulated to include arbitrary files.

Description

Multiple PHP remote file inclusion vulnerabilities in Supasite 1.23b allow remote attackers to execute arbitrary PHP code via a URL in the supa[db_path] parameter to (1) common_functions.php, (2) admin_auth_cookies.php, (3) admin_mods.php, (4) admin_news.php, (5) admin_topics.php, (6) admin_users.php, (7) admin_utilities.php, (8) site_comment.php, or (9) site_news.php; or the supa[include_path] parameter to (10) admin_settings.php or (11) backend_site.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by GoLd_M · textwebappsphp
https://www.exploit-db.com/exploits/3771

This is a writeup detailing multiple remote file inclusion vulnerabilities in Supasite v1.23b. It lists various endpoints where the 'supa[db_path]' or 'supa[include_path]' parameters can be manipulated to include arbitrary files.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: Supasite v1.23b
No auth needed
Prerequisites: Network access to the target application · Ability to craft HTTP requests to the vulnerable endpoints
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (15)

Core 15
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/33796
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38845
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38849
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38846
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38851
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38855
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38854
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38853
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/23581
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3771
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38847
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38848
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1492
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38850
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38852

Scores

EPSS 0.0703
EPSS Percentile 93.4%

Details

CWE
CWE-94
Status published
Products (1)
supasite/supasite 1.23b
Published Apr 24, 2007
Tracked Since Feb 18, 2026