CVE-2009-0966
YABSoft Mega File Hosting 1.2 - Remote Code Execution via URL Parameter in cross.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0966. PoCs published by Garry.
AI-analyzed exploit summary This exploit demonstrates a remote/local file inclusion vulnerability in Mega File Hosting software. It allows an attacker to include arbitrary files via the 'url' parameter in cross.php, leading to potential remote code execution or information disclosure.
Description
PHP remote file inclusion vulnerability in cross.php in YABSoft Mega File Hosting 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the url parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.
Exploits (1)
This exploit demonstrates a remote/local file inclusion vulnerability in Mega File Hosting software. It allows an attacker to include arbitrary files via the 'url' parameter in cross.php, leading to potential remote code execution or information disclosure.