CVE-2009-4315
CVE-2009-4315
Directory traversal vulnerability in admin/ajaxsave.php in Nuggetz CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to create or modify arbitrary files via a .. (dot dot) in the nugget parameter and a modified pagevalue parameter, as demonstrated by creating and accessing a .php file to execute arbitrary PHP code.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencepacketstormsecurity.org/0912-exploits/nuggetz-exec.txtunverifiedexploitdbwww.exploit-db.com/exploits/10378unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →