CVE-2009-1779
Frax.dk Php Recommend < 1.3 - Remote File Inclusion via form_include_template Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1779. PoCs published by scriptjunkie.
AI-analyzed exploit summary The exploit demonstrates an authentication bypass, remote file inclusion (RFI), and code injection in Php Recommend <=1.3 due to insufficient input validation and improper file handling in admin.php. The vulnerable code allows arbitrary file writes and remote code execution via crafted HTTP requests.
Description
PHP remote file inclusion vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the form_include_template parameter.
Exploits (1)
The exploit demonstrates an authentication bypass, remote file inclusion (RFI), and code injection in Php Recommend <=1.3 due to insufficient input validation and improper file handling in admin.php. The vulnerable code allows arbitrary file writes and remote code execution via crafted HTTP requests.