CVE-2009-4223
NUCLEIKR-Web < 1.1 - Remote Code Execution via DOCUMENT_ROOT Parameter
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4223. PoCs published by cr4wl3r. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in KR-Web <= 1.1b2. The vulnerability allows an attacker to include a remote file via the DOCUMENT_ROOT parameter in krgourl.php, potentially leading to remote code execution.
Description
PHP remote file inclusion vulnerability in adm/krgourl.php in KR-Web 1.1b2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in KR-Web <= 1.1b2. The vulnerability allows an attacker to include a remote file via the DOCUMENT_ROOT parameter in krgourl.php, potentially leading to remote code execution.