CVE-2008-4439
MartinWood Datafeed Studio < 1.6.2 - Remote Code Execution via INSTALL_FOLDER Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4439. PoCs published by Bug Researchers Group.
AI-analyzed exploit summary The exploit describes a remote file inclusion vulnerability in Datafeed Studio due to improper input sanitization. An attacker can include arbitrary remote PHP files via the INSTALL_FOLDER parameter in patch.php.
Description
PHP remote file inclusion vulnerability in admin/bin/patch.php in MartinWood Datafeed Studio before 1.6.3 allows remote attackers to execute arbitrary PHP code via a URL in the INSTALL_FOLDER parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
The exploit describes a remote file inclusion vulnerability in Datafeed Studio due to improper input sanitization. An attacker can include arbitrary remote PHP files via the INSTALL_FOLDER parameter in patch.php.