CVE-2009-4834
EXPLOITEDZeroboard 4.1 pl7 - Remote Code Execution via Crafted Parameter Name
Title source: llmExploitation Summary
CVE-2009-4834 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including SpeeDr00t.
AI-analyzed exploit summary This exploit targets a preg_replace() vulnerability in Zeroboard 4.1 pl7, allowing remote code execution via crafted HTTP requests. It creates a backdoor PHP shell by exploiting improper input validation in the REMOTE_ADDR parameter.
Description
lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibly related to now_connect.php.
Exploits (1)
This exploit targets a preg_replace() vulnerability in Zeroboard 4.1 pl7, allowing remote code execution via crafted HTTP requests. It creates a backdoor PHP shell by exploiting improper input validation in the REMOTE_ADDR parameter.