CVE-2007-2545
Persism CMS < 0.9.2 - Remote File Inclusion via system[path] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2545. PoCs published by GoLd_M.
AI-analyzed exploit summary This is a writeup describing multiple remote file inclusion vulnerabilities in Persism Content Management System <= 0.9.2. It lists various exploit paths but does not include actual exploit code or payloads.
Description
Multiple PHP remote file inclusion vulnerabilities in Persism CMS 0.9.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the system[path] parameter to (1) blocks/headerfile.php, (2) files/blocks/latest_files.php, (3) filters/headerfile.php, (4) forums/blocks/latest_posts.php, (5) groups/headerfile.php, (6) links/blocks/links.php, (7) menu/headerfile.php, (8) news/blocks/latest_news.php, (9) settings/headerfile.php, or (10) users/headerfile.php, in modules/.
Exploits (1)
This is a writeup describing multiple remote file inclusion vulnerabilities in Persism Content Management System <= 0.9.2. It lists various exploit paths but does not include actual exploit code or payloads.