Description
Multiple PHP remote file inclusion vulnerabilities in Pecio CMS 2.0.5 allow remote attackers to execute arbitrary PHP code via a URL in the template parameter to (1) post.php, (2) article.php, (3) blog.php, or (4) home.php in pec_templates/nova-blue/.
Exploits (1)
References (4)
Core 4
Core References
Exploit x_refsource_misc
http://packetstormsecurity.org/1008-exploits/peciocms-rfi.txt
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/61433
Exploit x_refsource_misc
http://eidelweiss-advisories.blogspot.com/2010/08/pecio-cms-v205-template-multiple-remote.html
Exploit exploit
x_refsource_exploit-db
http://www.exploit-db.com/exploits/14815
Scores
EPSS
0.0140
EPSS Percentile
80.5%
Details
CWE
CWE-94
Status
published
Products (1)
pecio-cms/pecio_cms
2.0.5
Published
Sep 03, 2010
Tracked Since
Feb 18, 2026