CVE-2009-1502
S-Cms 1.1 Stable and 1.5.2 - Path Traversal via Page Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1502. PoCs published by ZoRLu.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in S-Cms 1.1 Stable via the 'page' parameter in plugin.php. The vulnerability arises from unsanitized user input being directly included in a file path, allowing arbitrary file inclusion.
Description
Directory traversal vulnerability in plugin.php in S-Cms 1.1 Stable and 1.5.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in S-Cms 1.1 Stable via the 'page' parameter in plugin.php. The vulnerability arises from unsanitized user input being directly included in a file path, allowing arbitrary file inclusion.