First published: Fri Mar 26 2010(Updated: )
PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter, a different vector than CVE-2009-3220.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Aiocp | =1.4.001 | |
=1.4.001 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4747 is classified as a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2009-4747, update to a patched version of AIOCP that addresses this vulnerability.
CVE-2009-4747 affects All In One Control Panel (AIOCP) version 1.4.001.
CVE-2009-4747 allows remote attackers to execute arbitrary PHP code through insecure handling of the page parameter.
Yes, CVE-2009-4747 is a documented vulnerability that has been publicly disclosed.