CVE-2009-3362
SZNews 2.7 - Remote Code Execution via printnews.php3 id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3362. PoCs published by kurdish hackers team.
AI-analyzed exploit summary The exploit demonstrates a remote file inclusion vulnerability in SZNews 2.7 due to improper input sanitization in the 'id' parameter of printnews.php3. An attacker can include arbitrary files, potentially leading to remote code execution.
Description
PHP remote file inclusion vulnerability in printnews.php3 in SZNews 2.7 allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.
Exploits (1)
The exploit demonstrates a remote file inclusion vulnerability in SZNews 2.7 due to improper input sanitization in the 'id' parameter of printnews.php3. An attacker can include arbitrary files, potentially leading to remote code execution.