CVE-2009-4315

Nuggetz CMS 1.0 - Path Traversal and Arbitrary File Write via nugget Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-4315. PoCs published by Amol Naik.

AI-analyzed exploit summary This exploit demonstrates a remote code execution vulnerability in Nuggetz CMS 1.0 via unsanitized input in the 'ajaxsave.php' file. The attacker can create or overwrite files on the server by manipulating the 'nugget' and 'pagevalue' parameters, leading to arbitrary PHP code execution.

Description

Directory traversal vulnerability in admin/ajaxsave.php in Nuggetz CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to create or modify arbitrary files via a .. (dot dot) in the nugget parameter and a modified pagevalue parameter, as demonstrated by creating and accessing a .php file to execute arbitrary PHP code.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Amol Naik · textwebappsphp
https://www.exploit-db.com/exploits/10378

This exploit demonstrates a remote code execution vulnerability in Nuggetz CMS 1.0 via unsanitized input in the 'ajaxsave.php' file. The attacker can create or overwrite files on the server by manipulating the 'nugget' and 'pagevalue' parameters, leading to arbitrary PHP code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Nuggetz CMS 1.0
No auth needed
Prerequisites: Network access to the target server · Nuggetz CMS 1.0 installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/54699
Vendor Advisory x_refsource_confirm
http://www.nuggetz.co.uk/versionhistory.htm
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37664
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/60902

Scores

EPSS 0.0202
EPSS Percentile 78.3%

Details

CWE
CWE-22
Status published
Products (1)
nuggetz/nuggetz_cms 1.0
Published Dec 14, 2009
Tracked Since Feb 18, 2026