CVE-2009-4622

Drunken:Golem Gaming Portal 0.5.1 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-4622. PoCs published by EA Ngel.

AI-analyzed exploit summary This is a writeup describing a local file inclusion (LFI) vulnerability in an unspecified PHP application. The exploit leverages an unsafe include statement to read arbitrary files via path traversal.

Description

PHP remote file inclusion vulnerability in admin/admin_news_bot.php in Drunken:Golem Gaming Portal 0.5.1 alpha 2 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter, a different vector than CVE-2007-0572.

Exploits (1)

exploitdb WRITEUP VERIFIED
by EA Ngel · textwebappsphp
https://www.exploit-db.com/exploits/9635

This is a writeup describing a local file inclusion (LFI) vulnerability in an unspecified PHP application. The exploit leverages an unsafe include statement to read arbitrary files via path traversal.

Classification
Writeup 90%
Attack Type
Lfi
Complexity
Trivial
Reliability
Theoretical
Target: unspecified PHP application
No auth needed
Prerequisites: vulnerable PHP application with exposed admin_news_bot.php
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/53136
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9635

Scores

EPSS 0.0210
EPSS Percentile 79.3%

Details

CWE
CWE-94
Status published
Products (1)
legrinder/drunken\ golem_gaming_portal 0.5.1
Published Jan 18, 2010
Tracked Since Feb 18, 2026