CVE-2009-5095
ea gBook 0.1 and 0.1.4 - Remote Code Execution via inc_ordner Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-5095. PoCs published by bd0rk.
AI-analyzed exploit summary This exploit leverages a Remote File Inclusion (RFI) vulnerability in ea-gBook 0.1 to execute arbitrary commands. It sends crafted HTTP requests to include a malicious shell script and execute commands via the vulnerable 'inc_ordner' parameter.
Description
PHP remote file inclusion vulnerability in index_inc.php in ea gBook 0.1 and 0.1.4 allows remote attackers to execute arbitrary PHP code via a URL in the inc_ordner parameter.
Exploits (1)
This exploit leverages a Remote File Inclusion (RFI) vulnerability in ea-gBook 0.1 to execute arbitrary commands. It sends crafted HTTP requests to include a malicious shell script and execute commands via the vulnerable 'inc_ordner' parameter.