CVE-2009-3307

FSphp 0.2.1 - Remote File Inclusion via FSPHP_LIB Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-3307. PoCs published by NoGe.

AI-analyzed exploit summary The exploit demonstrates a remote file inclusion vulnerability in FSphp 0.2.1 by manipulating the `FSPHP_LIB` parameter in multiple PHP files, allowing an attacker to include arbitrary remote files.

Description

Multiple PHP remote file inclusion vulnerabilities in FSphp 0.2.1 allow remote attackers to execute arbitrary PHP code via a URL in the FSPHP_LIB parameter to (1) FSphp.php, (2) navigation.php, and (3) pathwrite.php in lib/.

Exploits (1)

exploitdb WORKING POC VERIFIED
by NoGe · textwebappsmultiple
https://www.exploit-db.com/exploits/9720

The exploit demonstrates a remote file inclusion vulnerability in FSphp 0.2.1 by manipulating the `FSPHP_LIB` parameter in multiple PHP files, allowing an attacker to include arbitrary remote files.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: FSphp version 0.2.1
No auth needed
Prerequisites: Remote file inclusion must be enabled on the target server · Attacker-controlled remote file with malicious PHP code
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9720
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/2704

Scores

EPSS 0.0492
EPSS Percentile 91.0%

Details

CWE
CWE-94
Status published
Products (1)
frank_lichtenheld/fsphp 0.2.1
Published Sep 23, 2009
Tracked Since Feb 18, 2026