Exploitation Summary
EIP tracks 1 public exploit for CVE-2005-0828. PoCs published by Majid NT.
AI-analyzed exploit summary This is a writeup describing an information disclosure vulnerability in RunCMS (formerly E-Xoops). The issue allows attackers to retrieve database configuration details by accessing a debug script with a crafted URL.
Description
highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allows remote attackers to read arbitrary PHP files by specifying the pathname in the file parameter, as demonstrated by reading database configuration information from mainfile.php.
Exploits (1)
This is a writeup describing an information disclosure vulnerability in RunCMS (formerly E-Xoops). The issue allows attackers to retrieve database configuration details by accessing a debug script with a crafted URL.