Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-4747. PoCs published by Hadi Kiamarsi.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Aiocp 1.4.001. The vulnerability allows an attacker to include and execute remote PHP files by manipulating the 'page' parameter in the 'cp_html2xhtmlbasic.php' script.
Description
PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter, a different vector than CVE-2009-3220.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Aiocp 1.4.001. The vulnerability allows an attacker to include and execute remote PHP files by manipulating the 'page' parameter in the 'cp_html2xhtmlbasic.php' script.