CVE-2009-3824
Greenwood PHP Content Manager 0.3.2 - Path Traversal via Content Path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3824. PoCs published by Khashayar Fereidani.
AI-analyzed exploit summary This exploit targets a remote code execution vulnerability in Greenwood Content Manager by injecting PHP code into the User-Agent header, which is then written to the server's access log and executed via a path traversal in the 'content_path' parameter.
Description
Directory traversal vulnerability in include/processor.php in Greenwood PHP Content Manager 0.3.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the content_path parameter.
Exploits (1)
This exploit targets a remote code execution vulnerability in Greenwood Content Manager by injecting PHP code into the User-Agent header, which is then written to the server's access log and executed via a path traversal in the 'content_path' parameter.