CVE-2009-3317
OpenSiteAdmin 0.9.7 BETA - Remote Code Execution via Path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3317. PoCs published by EA Ngel.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in OpenSiteAdmin 0.9.7 BETA via the 'path' parameter in pageHeader.php. The PoC provides a URL to trigger the vulnerability, allowing remote file inclusion.
Description
PHP remote file inclusion vulnerability in pages/pageHeader.php in OpenSiteAdmin 0.9.7 BETA allows remote attackers to execute arbitrary PHP code via a URL in the path parameter, a different vector than CVE-2008-0648.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in OpenSiteAdmin 0.9.7 BETA via the 'path' parameter in pageHeader.php. The PoC provides a URL to trigger the vulnerability, allowing remote file inclusion.