CVE-2009-0513
WebFrame 0.76 - Remote Code Execution via classFiles Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0513. PoCs published by ahmadbady.
AI-analyzed exploit summary This exploit demonstrates Remote File Inclusion (RFI) and Local File Inclusion (LFI) vulnerabilities in WebFrame 0.76. The vulnerabilities arise from unsanitized user input in the 'classFiles', 'currentmod', and 'LANG' parameters, allowing arbitrary file inclusion.
Description
Multiple PHP remote file inclusion vulnerabilities in WebFrame 0.76 allow remote attackers to execute arbitrary PHP code via a URL in the classFiles parameter to (1) admin/doc/index.php, (2) index.php, and (3) base/menu.php in mod/.
Exploits (1)
This exploit demonstrates Remote File Inclusion (RFI) and Local File Inclusion (LFI) vulnerabilities in WebFrame 0.76. The vulnerabilities arise from unsanitized user input in the 'classFiles', 'currentmod', and 'LANG' parameters, allowing arbitrary file inclusion.