CVE-2009-2331

CMS Chainuk <1.2 - Code Injection

Title source: llm
STIX 2.1

Description

Multiple static code injection vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to inject arbitrary PHP code (1) into settings.php via the menu parameter to admin_settings.php or (2) into a content/=NUMBER.php file via the title parameter to admin_new.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by eLwaux · textwebappsphp
https://www.exploit-db.com/exploits/9069

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9069
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/55672
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/55673

Scores

EPSS 0.0244
EPSS Percentile 85.3%

Details

CWE
CWE-94
Status published
Products (1)
cms.tut.su/cms_chainuk < 1.2
Published Jul 05, 2009
Tracked Since Feb 18, 2026