Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-1922. PoCs published by eidelweiss.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in 29o3 CMS. The vulnerability arises from insecure handling of the 'LibDir' parameter in multiple PHP files, allowing an attacker to include arbitrary remote files.
Description
Multiple PHP remote file inclusion vulnerabilities in 29o3 CMS 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the LibDir parameter to (1) lib/page/pageDescriptionObject.php, and (2) layoutHeaderFuncs.php, (3) layoutManager.php, and (4) layoutParser.php in lib/layout/.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in 29o3 CMS. The vulnerability arises from insecure handling of the 'LibDir' parameter in multiple PHP files, allowing an attacker to include arbitrary remote files.