CVE-2003-1239
WihPhoto 0.86 - Directory Traversal via Album and Pic Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2003-1239. PoCs published by frog.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in WihPhoto's sendphoto.php script, allowing remote attackers to read arbitrary files by manipulating the 'album' and 'pic' parameters. The vulnerability can be exploited to send sensitive files as email attachments.
Description
Directory traversal vulnerability in sendphoto.php in WihPhoto 0.86 allows remote attackers to read arbitrary files via .. specifiers in the album parameter, and the target filename in the pic parameter.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in WihPhoto's sendphoto.php script, allowing remote attackers to read arbitrary files by manipulating the 'album' and 'pic' parameters. The vulnerability can be exploited to send sensitive files as email attachments.