CVE-2010-3419
Haudenschilt Family Connections CMS 2.2.3 - Remote Code Execution via current_user_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-3419. PoCs published by LoSt.HaCkEr.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in FCMS 2.2.3, allowing an attacker to include arbitrary remote files via the 'current_user_id' parameter in 'familynews.php' and 'settings.php'. The exploit is straightforward and relies on user-supplied input to execute malicious code.
Description
Multiple PHP remote file inclusion vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the current_user_id parameter to (1) familynews.php and (2) settings.php.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in FCMS 2.2.3, allowing an attacker to include arbitrary remote files via the 'current_user_id' parameter in 'familynews.php' and 'settings.php'. The exploit is straightforward and relies on user-supplied input to execute malicious code.