Exploitation Summary
EIP tracks 1 public exploit for CVE-2004-1601. PoCs published by R00tCr4ck.
AI-analyzed exploit summary The exploit demonstrates multiple input validation vulnerabilities in CoolPHP, including XSS and file include attacks. It provides URLs to trigger these vulnerabilities, allowing an attacker to execute arbitrary scripts or steal cookie-based authentication credentials.
Description
Directory traversal vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to access arbitrary files and execute local PHP scripts via a .. (dot dot) in the op parameter.
Exploits (1)
The exploit demonstrates multiple input validation vulnerabilities in CoolPHP, including XSS and file include attacks. It provides URLs to trigger these vulnerabilities, allowing an attacker to execute arbitrary scripts or steal cookie-based authentication credentials.