Description
Multiple PHP remote file inclusion vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the current_user_id parameter to (1) familynews.php and (2) settings.php.
Exploits (1)
References (3)
Core 3
Core References
Exploit exploit
x_refsource_exploit-db
http://www.exploit-db.com/exploits/14965
Exploit x_refsource_misc
http://packetstormsecurity.org/1009-exploits/fcms-rfi.txt
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/61722
Scores
EPSS
0.0094
EPSS Percentile
76.3%
Details
CWE
CWE-94
Status
published
Products (1)
haudenschilt/family_connections_cms
2.2.3
Published
Sep 16, 2010
Tracked Since
Feb 18, 2026