CVE-2009-2923

BitmixSoft PHP-Lance 1.52 - Path Traversal via Language or Search Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-2923. PoCs published by jetli007.

AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in PHP-Lance v1.52. The vulnerability allows an attacker to read arbitrary files on the server by manipulating the 'language' or 'in' parameters in specific PHP scripts.

Description

Multiple directory traversal vulnerabilities in BitmixSoft PHP-Lance 1.52 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to show.php and (2) in parameter to advanced_search.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by jetli007 · textwebappsphp
https://www.exploit-db.com/exploits/9444

This exploit demonstrates a Local File Inclusion (LFI) vulnerability in PHP-Lance v1.52. The vulnerability allows an attacker to read arbitrary files on the server by manipulating the 'language' or 'in' parameters in specific PHP scripts.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: PHP-Lance v1.52
No auth needed
Prerequisites: Access to the vulnerable PHP scripts (show.php or advanced_search.php)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit vdb-entry x_refsource_osvdb
http://osvdb.org/57247
Exploit vdb-entry x_refsource_osvdb
http://osvdb.org/57246
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9444

Scores

EPSS 0.0438
EPSS Percentile 89.1%

Details

CWE
CWE-22
Status published
Products (1)
bitmixsoft/php-lance 1.52
Published Aug 21, 2009
Tracked Since Feb 18, 2026