CVE-2009-4231
SweetRice < 0.5.3 - Remote File Inclusion via Plugin Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4231. PoCs published by cr4wl3r.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in SweetRice <= 0.5.0. The vulnerability allows an attacker to include a remote file via the 'root_dir' parameter in the '_plugin/subscriber/inc/post.php' script, leading to potential remote code execution.
Description
Directory traversal vulnerability in as/lib/plugins.php in SweetRice 0.5.3 and earlier allows remote attackers to include and execute arbitrary local files via .. (dot dot) in the plugin parameter.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in SweetRice <= 0.5.0. The vulnerability allows an attacker to include a remote file via the 'root_dir' parameter in the '_plugin/subscriber/inc/post.php' script, leading to potential remote code execution.