CVE-2009-4977
MyBackup 1.4.0 - Authenticated Remote Code Execution via main_content Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4977. PoCs published by SirGod.
AI-analyzed exploit summary This exploit demonstrates Arbitrary File Download (AFD) and Remote File Inclusion (RFI) vulnerabilities in MyBackup 1.4.0. The AFD allows reading local files via path traversal, while the RFI requires authentication and can execute remote scripts.
Description
PHP remote file inclusion vulnerability in index.php in MyBackup 1.4.0 allows remote authenticated users to execute arbitrary PHP code via a URL in the main_content parameter.
Exploits (1)
This exploit demonstrates Arbitrary File Download (AFD) and Remote File Inclusion (RFI) vulnerabilities in MyBackup 1.4.0. The AFD allows reading local files via path traversal, while the RFI requires authentication and can execute remote scripts.