CVE-2009-0514
WebFrame 0.76 - Path Traversal and Arbitrary File Execution via currentmod and LANG Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0514. PoCs published by ahmadbady.
AI-analyzed exploit summary This exploit demonstrates Remote File Inclusion (RFI) and Local File Inclusion (LFI) vulnerabilities in WebFrame 0.76. The vulnerabilities arise from unsanitized user input in the 'classFiles', 'currentmod', and 'LANG' parameters, allowing arbitrary file inclusion.
Description
Multiple directory traversal vulnerabilities in WebFrame 0.76 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) currentmod and (2) LANG parameters to mod/index.php.
Exploits (1)
This exploit demonstrates Remote File Inclusion (RFI) and Local File Inclusion (LFI) vulnerabilities in WebFrame 0.76. The vulnerabilities arise from unsanitized user input in the 'classFiles', 'currentmod', and 'LANG' parameters, allowing arbitrary file inclusion.