CVE-2009-2784

dit.cms 1.3 - Path Traversal via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-2784. PoCs published by SirGod.

AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in dit.cms 1.3 due to improper input validation in multiple PHP scripts. The PoC includes URLs that leverage path traversal sequences to access arbitrary files (e.g., boot.ini) when register_globals is enabled.

Description

Multiple directory traversal vulnerabilities in dit.cms 1.3, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path parameter to index.php in (1) install/, (2) menus/left_rightslideopen/, (3) menus/side_pullout/, (4) menus/side_slideopen/, (5) menus/simple/, (6) menus/top_dropdown/, and (7) menus/topside/; the sitemap parameter to index.php in (8) menus/left_rightslideopen/, (9) menus/side_pullout/, (10) menus/side_slideopen/, (11) menus/top_dropdown/, and (12) menus/topside/; and the (13) relPath parameter to index/index.php. NOTE: PHP remote file inclusion vulnerabilities reportedly also exist for some of these vectors.

Exploits (1)

exploitdb WORKING POC VERIFIED
by SirGod · textwebappsphp
https://www.exploit-db.com/exploits/9310

This exploit demonstrates a Local File Inclusion (LFI) vulnerability in dit.cms 1.3 due to improper input validation in multiple PHP scripts. The PoC includes URLs that leverage path traversal sequences to access arbitrary files (e.g., boot.ini) when register_globals is enabled.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: dit.cms 1.3
No auth needed
Prerequisites: register_globals = on · access to vulnerable endpoints
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9310
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36076

Scores

EPSS 0.0372
EPSS Percentile 88.4%

Details

CWE
CWE-22
Status published
Products (1)
ditcms/dit.cms 1.3
Published Aug 17, 2009
Tracked Since Feb 18, 2026