.. / CVE-2009-4223

Exploit for KR-Web <=1.1b2 - Remote File Inclusion (CVE-2009-4223)

Description:

KR-Web 1.1b2 and prior contain a remote file inclusion vulnerability via adm/krgourl.php, which allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter.

Nuclei Template

View the template here CVE-2009-4223.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2009/CVE-2009-4223.yaml
Copy

References:

https://sourceforge.net/projects/krw/
http://www.exploit-db.com/exploits/10216
https://www.exploit-db.com/exploits/10216
https://nvd.nist.gov/vuln/detail/CVE-2009-4223
https://exchange.xforce.ibmcloud.com/vulnerabilities/54395