Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2792. PoCs published by SirGod.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Really Simple CMS 0.3a due to improper input validation in the 'PT' parameter in 'plugings/pagecontent.php'. The PoC shows how an attacker can traverse directories to include arbitrary files, such as 'boot.ini'.
Description
Directory traversal vulnerability in plugings/pagecontent.php in Really Simple CMS (RSCMS) 0.3a allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PT parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Really Simple CMS 0.3a due to improper input validation in the 'PT' parameter in 'plugings/pagecontent.php'. The PoC shows how an attacker can traverse directories to include arbitrary files, such as 'boot.ini'.