CVE-2007-5271
Trionic Cite CMS 1.2 rev9 - Remote Code Execution via bField[bf_data] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5271. PoCs published by GoLd_M.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Trionic Cite CMS 1.2 rev9. The PoC provides URLs that allow an attacker to include arbitrary remote files by manipulating the `bField[bf_data]` parameter.
Description
Multiple PHP remote file inclusion vulnerabilities in Trionic Cite CMS 1.2 rev9 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the bField[bf_data] parameter to (1) interface/editors/-custom.php or (2) interface/editors/custom.php.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Trionic Cite CMS 1.2 rev9. The PoC provides URLs that allow an attacker to include arbitrary remote files by manipulating the `bField[bf_data]` parameter.