CVE-2001-1334
PHPSlash 0.6.1 - Authenticated Arbitrary File Read via Block Source URL
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2001-1334. PoCs published by tobozo tagada.
AI-analyzed exploit summary This writeup describes an information disclosure vulnerability in PHPSlash where an authenticated admin can read arbitrary files by creating a URL block with a local file path. The exploit leverages improper input validation in blockAdmin.php3.
Description
Block_render_url.class in PHPSlash 0.6.1 allows remote attackers with PHPSlash administrator privileges to read arbitrary files by creating a block and specifying the target file as the source URL.
Exploits (1)
This writeup describes an information disclosure vulnerability in PHPSlash where an authenticated admin can read arbitrary files by creating a URL block with a local file path. The exploit leverages improper input validation in blockAdmin.php3.