CVE-2009-4747: Code Injection
Published Mar 26, 2010
·Updated
PHP remote file inclusion vulnerability in public/code/cphtml2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter, a different vector than CVE-2009-3220.
Affected Software
1 affected component
Tecnick Aiocp=1.4.001
Event History
Mar 26, 2010
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-4747?
CVE-2009-4747 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2009-4747?
To fix CVE-2009-4747, update to a patched version of AIOCP that addresses this vulnerability.
3
What systems are affected by CVE-2009-4747?
CVE-2009-4747 affects All In One Control Panel (AIOCP) version 1.4.001.
4
What type of attack does CVE-2009-4747 facilitate?
CVE-2009-4747 allows remote attackers to execute arbitrary PHP code through insecure handling of the page parameter.
5
Is CVE-2009-4747 a known vulnerability?
Yes, CVE-2009-4747 is a documented vulnerability that has been publicly disclosed.