CVE-2009-2769
Ultrize TimeSheet 1.2.2 - Remote Code Execution via config[include_dir] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2769. PoCs published by NoGe.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Ultrize TimeSheet 1.2.2. The vulnerability allows an attacker to include arbitrary remote files by manipulating the 'config[include_dir]' parameter in the 'timesheet.php' file.
Description
PHP remote file inclusion vulnerability in include/timesheet.php in Ultrize TimeSheet 1.2.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[include_dir] parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Ultrize TimeSheet 1.2.2. The vulnerability allows an attacker to include arbitrary remote files by manipulating the 'config[include_dir]' parameter in the 'timesheet.php' file.