CVE-2008-5332
Pie 0.5.3 - Remote Code Execution via PHP File Inclusion
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5332. PoCs published by NoGe.
AI-analyzed exploit summary This exploit demonstrates multiple remote file inclusion vulnerabilities in Pie Web M{a,e}sher 0.5.3. It allows an attacker to include arbitrary remote files via the 'lib' or 'GLOBALS[pie][library_path]' parameters in various PHP scripts.
Description
Multiple PHP remote file inclusion vulnerabilities in Pie 0.5.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lib parameter to files in lib/action/ including (a) alias.php, (b) cancel.php, (c) context.php, (d) deadlinks.php, (e) delete.php, and others; and the (2) GLOBALS[pie][library_path] parameter to files in lib/share/ including (f) diff.php, (g) file.php, (h) locale.php, (i) mapfile.php, (j) page.php, and others.
Exploits (1)
This exploit demonstrates multiple remote file inclusion vulnerabilities in Pie Web M{a,e}sher 0.5.3. It allows an attacker to include arbitrary remote files via the 'lib' or 'GLOBALS[pie][library_path]' parameters in various PHP scripts.