Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-0442. PoCs published by Osirys.
AI-analyzed exploit summary This exploit leverages a Local File Inclusion (LFI) vulnerability in PHPbbBook 1.3 to inject malicious PHP code into Apache logs, achieving Remote Command Execution (RCE). The script automates log poisoning and command execution via the LFI path.
Description
Directory traversal vulnerability in bbcode.php in PHPbbBook 1.3 and 1.3h allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the l parameter.
Exploits (1)
This exploit leverages a Local File Inclusion (LFI) vulnerability in PHPbbBook 1.3 to inject malicious PHP code into Apache logs, achieving Remote Command Execution (RCE). The script automates log poisoning and command execution via the LFI path.