CVE-2009-3306
ClearSite 4.50 - Remote Code Execution via cs_base_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3306. PoCs published by EA Ngel.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in the Network Management/Inventory System's header.php file. The attacker can include arbitrary remote files by manipulating the cs_base_path parameter.
Description
PHP remote file inclusion vulnerability in include/header.php in ClearSite 4.50 allows remote attackers to execute arbitrary PHP code via a URL in the cs_base_path parameter.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in the Network Management/Inventory System's header.php file. The attacker can include arbitrary remote files by manipulating the cs_base_path parameter.