The exploit demonstrates a Remote File Inclusion (RFI) vulnerability in CMSimple <= 4.4.2, where the `pth[folder][plugin]` parameter in `required_classes.php` is used to include arbitrary remote files, leading to potential remote code execution.
Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:CMSimple <= 4.4.2
No auth needed
Prerequisites:Access to the vulnerable endpoint · Remote file hosting with malicious payload