CVE-2009-3307
FSphp 0.2.1 - Remote File Inclusion via FSPHP_LIB Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3307. PoCs published by NoGe.
AI-analyzed exploit summary The exploit demonstrates a remote file inclusion vulnerability in FSphp 0.2.1 by manipulating the `FSPHP_LIB` parameter in multiple PHP files, allowing an attacker to include arbitrary remote files.
Description
Multiple PHP remote file inclusion vulnerabilities in FSphp 0.2.1 allow remote attackers to execute arbitrary PHP code via a URL in the FSPHP_LIB parameter to (1) FSphp.php, (2) navigation.php, and (3) pathwrite.php in lib/.
Exploits (1)
The exploit demonstrates a remote file inclusion vulnerability in FSphp 0.2.1 by manipulating the `FSPHP_LIB` parameter in multiple PHP files, allowing an attacker to include arbitrary remote files.