CVE-2010-2618

Insanevisions Adapcms - Code Injection

Title source: rule

Description

PHP remote file inclusion vulnerability in inc/smarty/libs/init.php in AdaptCMS 2.0.0 Beta, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the sitepath parameter. NOTE: it was later reported that 2.0.1 is also affected.

Exploits (2)

exploitdb WORKING POC VERIFIED
by v3n0m · rubywebappsphp
https://www.exploit-db.com/exploits/15237
exploitdb WORKING POC VERIFIED
by v3n0m · textwebappsphp
https://www.exploit-db.com/exploits/14016

Scores

EPSS 0.0210
EPSS Percentile 84.1%

Details

CWE
CWE-94
Status published
Products (2)
insanevisions/adapcms 2.0.0 beta
insanevisions/adapcms 2.0.1
Published Jul 02, 2010
Tracked Since Feb 18, 2026