CVE-2009-3511
justVisual 1.2 - Remote Code Execution via fs_jVroot Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3511. PoCs published by SirGod.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in justVisual 1.2 by manipulating the 'fs_jVroot' parameter to include arbitrary remote files. The PoC provides multiple endpoints where the vulnerability can be triggered.
Description
Multiple PHP remote file inclusion vulnerabilities in justVisual 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the fs_jVroot parameter to (1) sites/site/pages/index.php, (2) sites/test/pages/contact.php, (3) system/pageTemplate.php, and (4) system/utilities.php.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in justVisual 1.2 by manipulating the 'fs_jVroot' parameter to include arbitrary remote files. The PoC provides multiple endpoints where the vulnerability can be triggered.