CVE-2009-0495
REALTOR 747 4.11 - Remote Code Execution via INC_DIR Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0495. PoCs published by ahmadbady.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Realtor747 Version 4.11. The vulnerability is located in the '/include/define.php' file, where the 'INC_DIR' parameter is not properly sanitized, allowing an attacker to include remote files.
Description
PHP remote file inclusion vulnerability in include/define.php in REALTOR 747 4.11 allows remote attackers to execute arbitrary PHP code via a URL in the INC_DIR parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Realtor747 Version 4.11. The vulnerability is located in the '/include/define.php' file, where the 'INC_DIR' parameter is not properly sanitized, allowing an attacker to include remote files.