35619Third-party advisory
http://secunia.com/advisories/35619 CVE-2009-2396
WordPress Plugin DM Albums 1.9.2 - Remote File Inclusion
Record summary
CVE-2009-2396 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.
Description
PHP remote file inclusion vulnerability in template/album.php in DM Albums 1.9.2, as used standalone or as a WordPress plugin, allows remote attackers to execute arbitrary PHP code via a URL in the SECURITY_FILE parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin DM Albums 1.9.2 - Remote File InclusionExploitDB exploitby Septemb0xNot analyzed1 file
References
49043exploit
http://www.exploit-db.com/exploits/9043 35521vdb entry
http://www.securityfocus.com/bid/35521 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-2396