Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-3220. PoCs published by Hadi Kiamarsi.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in AIOCP 1.4.001 due to insufficient sanitization of the 'page' parameter in 'cp_html2txt.php'. An attacker can include a remote shell by manipulating the parameter.
Description
PHP remote file inclusion vulnerability in cp_html2txt.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in AIOCP 1.4.001 due to insufficient sanitization of the 'page' parameter in 'cp_html2txt.php'. An attacker can include a remote shell by manipulating the parameter.