CVE-2009-4224
SweetRice < 0.5.4 - Remote File Inclusion via root_dir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4224. PoCs published by cr4wl3r.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in SweetRice <= 0.5.0. The vulnerability allows an attacker to include a remote file via the 'root_dir' parameter in the '_plugin/subscriber/inc/post.php' script, leading to potential remote code execution.
Description
Multiple PHP remote file inclusion vulnerabilities in SweetRice 0.5.4, 0.5.3, and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_dir parameter to (1) _plugin/subscriber/inc/post.php and (2) as/lib/news_modify.php.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in SweetRice <= 0.5.0. The vulnerability allows an attacker to include a remote file via the 'root_dir' parameter in the '_plugin/subscriber/inc/post.php' script, leading to potential remote code execution.