CVE-2009-4623
Advanced Comment System 1.0 - Multiple Remote File Inclusions
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
5Exploited in Wild
-Decision
Descriptions
Multiple PHP remote file inclusion vulnerabilities in Advanced Comment System 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the ACS_path parameter to (1) index.php and (2) admin.php in advanced_comment_system/. NOTE: this might only be a vulnerability when the administrator has not followed installation instructions in install.php. NOTE: this might be the same as CVE-2020-35598.
Multiples vulnerabilidades de inclusión de fichero remoto PHP en Advanced Comment System versión 1.0. Permiten a atacantes remotos ejecutar código PHP de su elección a través de una URL en el parámetro ACS_path de (1) index.php y (2) admin.php de advanced_comment_system/. NOTA: esta vulnerabilidad sólo se puede producir si el administrador no ha seguido las instrucciones de instalación de install.php. NOTA: esto podría ser lo mismo que CVE-2020-35598
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-09-10 First Exploit
- 2010-01-18 CVE Reserved
- 2010-01-18 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (6)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/9623 | 2009-09-10 | |
https://github.com/MonsempesSamuel/CVE-2009-4623 | 2022-10-12 | |
https://github.com/kernel-cyber/CVE-2009-4623 | 2022-09-15 | |
https://github.com/hupe1980/CVE-2009-4623 | 2022-08-19 | |
http://www.exploit-db.com/exploits/9623 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/36643 | 2021-02-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Plohni Search vendor "Plohni" | Advanced Comment System Search vendor "Plohni" for product "Advanced Comment System" | 1.0 Search vendor "Plohni" for product "Advanced Comment System" and version "1.0" | - |
Affected
|