CVE-2008-0648

OpenSiteAdmin < 0.9.1.1 - Remote Code Execution via Path Parameter in Multiple Scripts

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-0648. PoCs published by Trancek.

AI-analyzed exploit summary This exploit demonstrates a local file inclusion (LFI) vulnerability in OpenSiteAdmin 0.9.1 BETA due to improper handling of the 'path' parameter in multiple PHP scripts. The vulnerability allows remote attackers to include arbitrary files via null byte injection, provided that 'Register Globals' is enabled and 'Magic_quotes_gpc' is disabled.

Description

Multiple PHP remote file inclusion vulnerabilities in OpenSiteAdmin 0.9.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) indexFooter.php; and (2) DatabaseManager.php, (3) FieldManager.php, (4) Filter.php, (5) Form.php, (6) FormManager.php, (7) LoginManager.php, and (8) Filters/SingleFilter.php in scripts/classes/.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Trancek · textwebappsphp
https://www.exploit-db.com/exploits/5068

This exploit demonstrates a local file inclusion (LFI) vulnerability in OpenSiteAdmin 0.9.1 BETA due to improper handling of the 'path' parameter in multiple PHP scripts. The vulnerability allows remote attackers to include arbitrary files via null byte injection, provided that 'Register Globals' is enabled and 'Magic_quotes_gpc' is disabled.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: OpenSiteAdmin 0.9.1 BETA and prior versions
No auth needed
Prerequisites: Register Globals: On · Magic_quotes_gpc: Off
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5068
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27640

Scores

EPSS 0.0186
EPSS Percentile 76.4%

Details

CWE
CWE-94
Status published
Products (1)
opensiteadmin/opensiteadmin < 0.9.1.1
Published Feb 07, 2008
Tracked Since Feb 18, 2026