CVE-2009-4623 describes multiple remote file inclusion (RFI) vulnerabilities in Advanced Comment System 1.0. The vulnerabilities exist in index.php and admin.php within the advanced_comment_system/ directory, where the ACS_path parameter is not properly sanitized, allowing attackers to include and execute arbitrary PHP code from remote sources. The vulnerability may only be present if the administrator has not followed the installation instructions provided in install.php.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Bash script exploit (CVE-2009-4623.sh) targeting CVE-2009-4623, a remote code execution vulnerability in Advanced Comment System (ACS). The exploit works by sending a specially crafted HTTP POST request to the admin.php page of a vulnerable ACS installation, injecting PHP code that executes arbitrary system commands via the system() function. The script checks for successful exploitation by looking for a known string in the response, then provides a non-interactive shell-like interface for the attacker to execute further commands. The README provides usage instructions and an example target URL. The repository is simple, with only two files: the exploit script and a README. The main attack vector is network-based, exploiting a web application endpoint. The exploit is operational, providing real command execution on the target if successful.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.