CVE-2009-2773

PHP Paid 4 Mail Script - Remote Code Execution via home.php page Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-2773. PoCs published by int_main();.

AI-analyzed exploit summary This is a writeup describing a file inclusion vulnerability in PHP Paid 4 Mail Script. The exploit demonstrates how an attacker can include remote files via the 'page' parameter in home.php, but no functional exploit code is provided.

Description

PHP remote file inclusion vulnerability in home.php in PHP Paid 4 Mail Script allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by int_main(); · textwebappsphp
https://www.exploit-db.com/exploits/9269

This is a writeup describing a file inclusion vulnerability in PHP Paid 4 Mail Script. The exploit demonstrates how an attacker can include remote files via the 'page' parameter in home.php, but no functional exploit code is provided.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: PHP Paid 4 Mail Script
No auth needed
Prerequisites: vulnerable version of PHP Paid 4 Mail Script · remote file inclusion enabled on the server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit vdb-entry x_refsource_osvdb
http://osvdb.org/56573
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35972
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9269
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/52015

Scores

EPSS 0.0289
EPSS Percentile 85.1%

Details

CWE
CWE-94
Status published
Products (1)
shop-020/php_paid_4_mail_script
Published Aug 14, 2009
Tracked Since Feb 18, 2026