Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-4810. PoCs published by LoSt.HaCkEr.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in AWCM v2.1 final, allowing an attacker to include arbitrary remote files via the 'theme_file' and 'lang_file' parameters in multiple PHP scripts.
Description
Multiple PHP remote file inclusion vulnerabilities in AR Web Content Manager (AWCM) 2.1 final allow remote attackers to execute arbitrary PHP code via a URL in the theme_file parameter to (1) includes/window_top.php and (2) header.php, and the (3) lang_file parameter to control/common.php.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in AWCM v2.1 final, allowing an attacker to include arbitrary remote files via the 'theme_file' and 'lang_file' parameters in multiple PHP scripts.