CVE-2008-2649
DesktopOnNet 3 Beta - Remote Code Execution via app_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2649. PoCs published by MK.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in DesktopOnNet 3 Beta by manipulating the 'app_path' parameter to include arbitrary remote files. The PoC provides URLs that can be used to execute malicious scripts by injecting a shell path.
Description
Multiple PHP remote file inclusion vulnerabilities in DesktopOnNet 3 Beta allow remote attackers to execute arbitrary PHP code via a URL in the app_path parameter to (1) don3_requiem.don3app/don3_requiem.php and (2) frontpage.don3app/frontpage.php.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in DesktopOnNet 3 Beta by manipulating the 'app_path' parameter to include arbitrary remote files. The PoC provides URLs that can be used to execute malicious scripts by injecting a shell path.