CVE-2009-3694
ezRecipe-Zee 91 - Path Traversal via cfg[prePath] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3694. PoCs published by kaMtiEz.
AI-analyzed exploit summary This Perl script exploits a Remote File Inclusion (RFI) vulnerability in EZRecipeZee CMS v91 by injecting a malicious URL into the 'cfg[prePath]' parameter, allowing remote command execution via a user-provided shell script.
Description
Directory traversal vulnerability in config/config.php in ezRecipe-Zee 91, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cfg[prePath] parameter.
Exploits (1)
This Perl script exploits a Remote File Inclusion (RFI) vulnerability in EZRecipeZee CMS v91 by injecting a malicious URL into the 'cfg[prePath]' parameter, allowing remote command execution via a user-provided shell script.