CVE-2008-2396
microSSys CMS < 1.5 - Remote Code Execution via PAGES Array Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2396. PoCs published by Raz0r.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in microSSys CMS <= 1.5. The vulnerability arises from improper handling of user-supplied input in the '1' and 'PAGES' parameters, allowing an attacker to include arbitrary remote files.
Description
PHP remote file inclusion vulnerability in index.php in Wajox Software microSSys CMS 1.5 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in an arbitrary element of the PAGES array parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in microSSys CMS <= 1.5. The vulnerability arises from improper handling of user-supplied input in the '1' and 'PAGES' parameters, allowing an attacker to include arbitrary remote files.