CVE-2008-1123
SiteBuilder Elite 1.2 - Remote Code Execution via CarpPath Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1123. PoCs published by MhZ91.
AI-analyzed exploit summary This is a writeup describing a remote file inclusion vulnerability in SiteBuilderElite 1.2. The vulnerability is due to the 'CarpPath' variable not being properly defined in files like 'carprss.php' and 'amazon-bestsellers.php', allowing remote code execution via crafted HTTP requests.
Description
Multiple PHP remote file inclusion vulnerabilities in SiteBuilder Elite 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the CarpPath parameter to (1) files/carprss.php and (2) files/amazon-bestsellers.php.
Exploits (1)
This is a writeup describing a remote file inclusion vulnerability in SiteBuilderElite 1.2. The vulnerability is due to the 'CarpPath' variable not being properly defined in files like 'carprss.php' and 'amazon-bestsellers.php', allowing remote code execution via crafted HTTP requests.