CVE-2009-0643

Simple PHP News 1.0 - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-0643. PoCs published by Osirys.

AI-analyzed exploit summary This exploit targets a remote command execution vulnerability in Simple PHP News 1.0 Final by injecting malicious PHP code into the 'post' parameter, which is then executed via the 'display.php' script. It requires Magic Quotes to be off and provides an interactive shell upon successful exploitation.

Description

Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary PHP code into news.txt via the post parameter, and then execute the code via a direct request to display.php. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Osirys · perlwebappsphp
https://www.exploit-db.com/exploits/7999

This exploit targets a remote command execution vulnerability in Simple PHP News 1.0 Final by injecting malicious PHP code into the 'post' parameter, which is then executed via the 'display.php' script. It requires Magic Quotes to be off and provides an interactive shell upon successful exploitation.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Simple PHP News 1.0 Final
No auth needed
Prerequisites: Magic Quotes must be disabled on the target server · Target must be running Simple PHP News 1.0 Final
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7999
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/51816
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33814
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0357
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/48829

Scores

EPSS 0.0481
EPSS Percentile 90.8%

Details

CWE
CWE-94
Status published
Products (1)
dminnich/simple_php_news 1.0
Published Feb 20, 2009
Tracked Since Feb 18, 2026