CVE-2009-4156
Ciamos CMS < 0.9.5 - Remote Code Execution via module_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4156. PoCs published by cr4wl3r.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in Ciamos CMS <= 0.9.5. The vulnerability exists in the 'module_path' parameter in the 'pms' module, allowing an attacker to include remote files and execute arbitrary code.
Description
PHP remote file inclusion vulnerability in modules/pms/index.php in Ciamos CMS 0.9.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_path parameter.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in Ciamos CMS <= 0.9.5. The vulnerability exists in the 'module_path' parameter in the 'pms' module, allowing an attacker to include remote files and execute arbitrary code.