CVE-2008-0289

Member Area System < 1.7 - Remote Code Execution via view_func.php i Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-0289. PoCs published by ShipNX.

AI-analyzed exploit summary The exploit describes a remote file inclusion vulnerability in Members Area System 1.7 due to improper input sanitization. An attacker can include arbitrary remote PHP files via the 'i' parameter in view_func.php, leading to remote code execution.

Description

PHP remote file inclusion vulnerability in view_func.php in Member Area System (MAS) 1.7 and possibly others allows remote attackers to execute arbitrary PHP code via a URL in the i parameter. NOTE: a second vector might exist via the l parameter. NOTE: as of 20080118, the vendor has disputed the set of affected versions, stating that the issue "is already fixed, for almost a year."

Exploits (1)

exploitdb WRITEUP VERIFIED
by ShipNX · textwebappsphp
https://www.exploit-db.com/exploits/31011

The exploit describes a remote file inclusion vulnerability in Members Area System 1.7 due to improper input sanitization. An attacker can include arbitrary remote PHP files via the 'i' parameter in view_func.php, leading to remote code execution.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: Members Area System 1.7
No auth needed
Prerequisites: Remote file hosting with malicious PHP code · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/39611
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3547
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/486618/100/0/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/486172/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27244

Scores

EPSS 0.0222
EPSS Percentile 84.7%

Details

CWE
CWE-94
Status published
Products (1)
mansion_productions/member_area_system < 1.7
Published Jan 16, 2008
Tracked Since Feb 18, 2026