CVE-2009-4220
PointComma < 3.8b2 - Remote Code Execution via pcConfig[smartyPath] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4220. PoCs published by cr4wl3r.
AI-analyzed exploit summary This is a writeup describing a remote file inclusion vulnerability in PointComma <= 3.8b2. The vulnerability allows an attacker to include a remote file via the `pcConfig[smartyPath]` parameter in `pctemplate.php`.
Description
PHP remote file inclusion vulnerability in includes/classes/pctemplate.php in PointComma 3.8b2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pcConfig[smartyPath] parameter.
Exploits (1)
This is a writeup describing a remote file inclusion vulnerability in PointComma <= 3.8b2. The vulnerability allows an attacker to include a remote file via the `pcConfig[smartyPath]` parameter in `pctemplate.php`.