CVE-2008-2977
Ourvideo CMS 9.5 - Remote Code Execution via include_connection Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2977. PoCs published by CraCkEr.
AI-analyzed exploit summary This exploit demonstrates Remote File Inclusion (RFI), Local File Inclusion (LFI), and Cross-Site Scripting (XSS) vulnerabilities in Ourvideo CMS 9.5. It provides URLs to exploit these vulnerabilities by injecting malicious input into specific parameters.
Description
Multiple PHP remote file inclusion vulnerabilities in Ourvideo CMS 9.5 allow remote attackers to execute arbitrary PHP code via a URL in the include_connection parameter to (1) edit_top_feature.php and (2) edit_topics_feature.php in phpi/.
Exploits (1)
This exploit demonstrates Remote File Inclusion (RFI), Local File Inclusion (LFI), and Cross-Site Scripting (XSS) vulnerabilities in Ourvideo CMS 9.5. It provides URLs to exploit these vulnerabilities by injecting malicious input into specific parameters.