CVE-2010-1337
Lussumo Vanilla < 1.1.10 - Remote Code Execution via PHP File Inclusion
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-1337. PoCs published by eidelweiss.
AI-analyzed exploit summary The code describes a remote file inclusion vulnerability in Vanilla 1.1.10 and prior versions due to insufficient sanitization of user-supplied data in the 'include' and 'Configuration[LANGUAGE]' parameters. Exploitation could lead to remote code execution or other attacks.
Description
Multiple PHP remote file inclusion vulnerabilities in definitions.php in Lussumo Vanilla 1.1.10, and possibly 0.9.2 and other versions, allow remote attackers to execute arbitrary PHP code via a URL in the (1) include and (2) Configuration['LANGUAGE'] parameters.
Exploits (1)
The code describes a remote file inclusion vulnerability in Vanilla 1.1.10 and prior versions due to insufficient sanitization of user-supplied data in the 'include' and 'Configuration[LANGUAGE]' parameters. Exploitation could lead to remote code execution or other attacks.