CVE-2009-2223

LightOpenCMS 0.1 - Path Traversal via cwd Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-2223. PoCs published by JosS.

AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in LightOpenCMS 0.1 due to improper handling of the 'cwd' parameter in smarty.php. By manipulating the parameter, an attacker can include arbitrary files, such as boot.ini, leading to potential information disclosure or further exploitation.

Description

Directory traversal vulnerability in locms/smarty.php in LightOpenCMS 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cwd parameter. NOTE: remote file inclusion attacks may be possible.

Exploits (1)

exploitdb WORKING POC VERIFIED
by JosS · textwebappsphp
https://www.exploit-db.com/exploits/9015

This exploit demonstrates a Local File Inclusion (LFI) vulnerability in LightOpenCMS 0.1 due to improper handling of the 'cwd' parameter in smarty.php. By manipulating the parameter, an attacker can include arbitrary files, such as boot.ini, leading to potential information disclosure or further exploitation.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: LightOpenCMS 0.1
No auth needed
Prerequisites: register_globals must be enabled in php.ini
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9015

Scores

EPSS 0.0376
EPSS Percentile 88.5%

Details

CWE
CWE-22
Status published
Products (1)
teozkr/lightopencms 0.1
Published Jun 26, 2009
Tracked Since Feb 18, 2026