CVE-2008-1123

SiteBuilder Elite 1.2 - Remote Code Execution via CarpPath Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-1123. PoCs published by MhZ91.

AI-analyzed exploit summary This is a writeup describing a remote file inclusion vulnerability in SiteBuilderElite 1.2. The vulnerability is due to the 'CarpPath' variable not being properly defined in files like 'carprss.php' and 'amazon-bestsellers.php', allowing remote code execution via crafted HTTP requests.

Description

Multiple PHP remote file inclusion vulnerabilities in SiteBuilder Elite 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the CarpPath parameter to (1) files/carprss.php and (2) files/amazon-bestsellers.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by MhZ91 · textwebappsphp
https://www.exploit-db.com/exploits/5199

This is a writeup describing a remote file inclusion vulnerability in SiteBuilderElite 1.2. The vulnerability is due to the 'CarpPath' variable not being properly defined in files like 'carprss.php' and 'amazon-bestsellers.php', allowing remote code execution via crafted HTTP requests.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: SiteBuilderElite 1.2
No auth needed
Prerequisites: Network access to the target application · Ability to send crafted HTTP requests
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28036
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5199

Scores

EPSS 0.0169
EPSS Percentile 74.1%

Details

CWE
CWE-94
Status published
Products (1)
sitebuilder/sitebuilder_elite 1.2
Published Mar 03, 2008
Tracked Since Feb 18, 2026