CVE-2009-1781
Frax.dk Php Recommend < 1.3 - Remote PHP Code Injection via form_aula Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1781. PoCs published by scriptjunkie.
AI-analyzed exploit summary The exploit demonstrates an authentication bypass, remote file inclusion (RFI), and code injection in Php Recommend <=1.3 due to insufficient input validation and improper file handling in admin.php. The vulnerable code allows arbitrary file writes and remote code execution via crafted HTTP requests.
Description
Static code injection vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to inject arbitrary PHP code into phpre_config.php via the form_aula parameter.
Exploits (1)
The exploit demonstrates an authentication bypass, remote file inclusion (RFI), and code injection in Php Recommend <=1.3 due to insufficient input validation and improper file handling in admin.php. The vulnerable code allows arbitrary file writes and remote code execution via crafted HTTP requests.