CVE-2015-9227
HIGHAlegroCart 1.2.8 - Authenticated Remote Code Execution via File Path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-9227. PoCs published by Curesec Research Team.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) and Remote File Inclusion (RFI) vulnerability in AlegroCart 1.2.8. The vulnerability allows an authenticated attacker to include and execute arbitrary local or remote files via the `file_path` parameter in the `report_logs` controller.
Description
PHP remote file inclusion vulnerability in the get_file function in upload/admin2/controller/report_logs.php in AlegroCart 1.2.8 allows remote administrators to execute arbitrary PHP code via a URL in the file_path parameter to upload/admin2.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) and Remote File Inclusion (RFI) vulnerability in AlegroCart 1.2.8. The vulnerability allows an authenticated attacker to include and execute arbitrary local or remote files via the `file_path` parameter in the `report_logs` controller.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H