CVE-2009-4435

F3Site 2009 - Path Traversal via GLOBALS[nlang] Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2009-4435. PoCs published by cr4wl3r.

AI-analyzed exploit summary The provided text describes a local file inclusion (LFI) vulnerability in F3Site 2009 due to insufficient input sanitization. The exploit involves manipulating the 'GLOBALS[nlang]' parameter to include arbitrary local files, potentially leading to further system compromise.

Description

Multiple directory traversal vulnerabilities in F3Site 2009 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the GLOBALS[nlang] parameter to (1) mod/poll.php and (2) mod/new.php.

Exploits (2)

exploitdb WRITEUP VERIFIED
by cr4wl3r · textwebappsphp
https://www.exploit-db.com/exploits/33419

The provided text describes a local file inclusion (LFI) vulnerability in F3Site 2009 due to insufficient input sanitization. The exploit involves manipulating the 'GLOBALS[nlang]' parameter to include arbitrary local files, potentially leading to further system compromise.

Classification
Writeup 80%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: F3Site 2009
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by cr4wl3r · textwebappsphp
https://www.exploit-db.com/exploits/33420

The provided text describes a local file inclusion (LFI) vulnerability in F3Site 2009 due to insufficient sanitization of user-supplied data. The example URL demonstrates how an attacker could exploit this by injecting a null byte to include arbitrary local files.

Classification
Writeup 80%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: F3Site 2009
No auth needed
Prerequisites: Access to the vulnerable application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/37408
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/54908
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/10536

Scores

EPSS 0.0201
EPSS Percentile 78.3%

Details

CWE
CWE-22
Status published
Products (1)
compmaster.prv.pl/f3site 2009
Published Dec 28, 2009
Tracked Since Feb 18, 2026