CVE-2009-2399
DM FileManager 3.9.4 - Remote Code Execution via SECURITY_FILE Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2399. PoCs published by Septemb0x.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in DM FileManager 3.9.4. The vulnerability allows an attacker to include a remote PHP file via the 'SECURITY_FILE' parameter in 'album.php', leading to potential remote code execution.
Description
PHP remote file inclusion vulnerability in dm-albums/template/album.php in DM FileManager 3.9.4, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the SECURITY_FILE parameter.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in DM FileManager 3.9.4. The vulnerability allows an attacker to include a remote PHP file via the 'SECURITY_FILE' parameter in 'album.php', leading to potential remote code execution.