CVE-2009-4472
PHPope < 1.0.0 - Remote Code Execution via GLOBALS Parameter Manipulation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4472. PoCs published by cr4wl3r.
AI-analyzed exploit summary This is a writeup describing a remote file inclusion vulnerability in PHPope <= 1.0.0. It provides URLs to exploit the vulnerability but does not include functional exploit code.
Description
Multiple PHP remote file inclusion vulnerabilities in PHPope 1.0.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[config][dir][plugins] parameter to plugins/address/admin/index.php, (2) GLOBALS[config][dir][functions] parameter to plugins/im/compose.php, and (3) GLOBALS[config][dir][classes] parameter to plugins/cssedit/admin/index.php.
Exploits (1)
This is a writeup describing a remote file inclusion vulnerability in PHPope <= 1.0.0. It provides URLs to exploit the vulnerability but does not include functional exploit code.